TY - GEN
T1 - Minimal disclosure in hierarchical Hippocratic databases with delegation
AU - Massacci, F.
AU - Mylopoulos, J.
AU - Zannone, N.
PY - 2005
Y1 - 2005
N2 - Hippocratic Databases have been proposed as a mechanism to guarantee the respect of privacy principles in data management. We argue that three major principles are missing from the proposed mechanism: hierarchies of purposes, delegation of tasks and authorizations (i.e. outsourcing), and the minimal disclosure of private information. In this paper, we propose a flexible framework for the negotiation of personal information among customers and (possibly virtual) enterprises based on user preferences when enterprises may adopt different processes to provide the same service. We use a goal-oriented approach to analyze the purposes of a Hippocratic system and derive a purpose and delegation hierarchy. Based on this hierarchy, effective algorithms are given to determine the minimum set of authorizations needed for a service. In this way, the minimal authorization table of a global business process can be automatically constructed from the collection of privacy policy tables associated with the collaborating enterprises. By using effective online algorithms, the derivation of such minimal information can also be done on-the-fly by the customer wishing to use the services of a virtual organization. © Springer-Verlag Berlin Heidelberg 2005.
AB - Hippocratic Databases have been proposed as a mechanism to guarantee the respect of privacy principles in data management. We argue that three major principles are missing from the proposed mechanism: hierarchies of purposes, delegation of tasks and authorizations (i.e. outsourcing), and the minimal disclosure of private information. In this paper, we propose a flexible framework for the negotiation of personal information among customers and (possibly virtual) enterprises based on user preferences when enterprises may adopt different processes to provide the same service. We use a goal-oriented approach to analyze the purposes of a Hippocratic system and derive a purpose and delegation hierarchy. Based on this hierarchy, effective algorithms are given to determine the minimum set of authorizations needed for a service. In this way, the minimal authorization table of a global business process can be automatically constructed from the collection of privacy policy tables associated with the collaborating enterprises. By using effective online algorithms, the derivation of such minimal information can also be done on-the-fly by the customer wishing to use the services of a virtual organization. © Springer-Verlag Berlin Heidelberg 2005.
UR - https://www.scopus.com/pages/publications/33646066334
UR - https://www.scopus.com/pages/publications/33646066334#tab=citedBy
U2 - 10.1007/11555827_25
DO - 10.1007/11555827_25
M3 - Conference contribution
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 438
EP - 454
BT - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
T2 - 10th European Symposium on Research in Computer Security, ESORICS 2005
Y2 - 12 September 2005 through 14 September 2005
ER -