Towards a Declarative Approach to Stateful and Stateless Usage Control for Data Protection
Francesco Di Cerbo, Fabio Martinelli, Ilaria Matteucci, Paolo Mori
2018
Abstract
Virtually any online website or service has a rising need for data protection mechanisms, especially for personal data, considering initiatives such as the new General Data Protection Regulation to operate on the EU economic space, or the Cybersecurity Law for the Chinese market. It seems therefore necessary to dispose of mechanisms that help both users, as well as legal experts and practitioners to automatically manage the processing of personal and sensitive data in a secure and compliant manner, to reduce the probability of human errors. To this aim, we show here our initial proposal for an automatically enforceable policy language, UPOL, for access and usage control of personal information, aiming at transparent and accountable data usage. UPOL extends and combines previous research results, U-XACML and PPL, and it is part of a more general proposal to regulate multi-party data sharing operations. A use case is proposed, considering challenges brought by the new EU’s GDPR.
DownloadPaper Citation
in Harvard Style
Di Cerbo F., Martinelli F., Matteucci I. and Mori P. (2018). Towards a Declarative Approach to Stateful and Stateless Usage Control for Data Protection.In Proceedings of the 14th International Conference on Web Information Systems and Technologies - Volume 1: WEBIST, ISBN 978-989-758-324-7, pages 308-315. DOI: 10.5220/0006962503080315
in Bibtex Style
@conference{webist18,
author={Francesco Di Cerbo and Fabio Martinelli and Ilaria Matteucci and Paolo Mori},
title={Towards a Declarative Approach to Stateful and Stateless Usage Control for Data Protection},
booktitle={Proceedings of the 14th International Conference on Web Information Systems and Technologies - Volume 1: WEBIST,},
year={2018},
pages={308-315},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0006962503080315},
isbn={978-989-758-324-7},
}
in EndNote Style
TY - CONF
JO - Proceedings of the 14th International Conference on Web Information Systems and Technologies - Volume 1: WEBIST,
TI - Towards a Declarative Approach to Stateful and Stateless Usage Control for Data Protection
SN - 978-989-758-324-7
AU - Di Cerbo F.
AU - Martinelli F.
AU - Matteucci I.
AU - Mori P.
PY - 2018
SP - 308
EP - 315
DO - 10.5220/0006962503080315