Show simple item record

dc.contributor.authorKagal, Lalana
dc.contributor.authorPato, Joseph
dc.date.accessioned2012-06-14T14:00:36Z
dc.date.available2012-06-14T14:00:36Z
dc.date.issued2010-07
dc.date.submitted2010-04
dc.identifier.issn1540-7993
dc.identifier.otherINSPEC Accession Number: 11447356
dc.identifier.urihttp://hdl.handle.net/1721.1/71140
dc.description.abstractDifferent organizations are constantly collecting, analyzing, and storing individuals' private data: shopping sites want to provide better service and recommendations, hospitals to improve healthcare, and government agencies to enable national defense and law enforcement. Sharing data lets these organizations discover important knowledge and draw useful conclusions but raises concerns about information privacy and trust. Until recently, the focus was on restricting access to data on a "need-to-know" basis, but since the 9/11 Commission, the paradigm has shifted to a "need to share." The authors explore the use of semantic privacy policies, justifications for data requests, and automated auditing to encourage sharing of sensitive data between organizations. They describe an architecture based on policy tools that evaluate incoming queries against semantic policies and domain knowledge and provide a justification for each query-why they're permitted, denied, or inapplicable. Using a semantic policy language gives policies explicit semantics that allow all participants to unambiguously understand their meaning. The justifications generated by checking incoming requests against these policies help requesters formulate privacy-aware queries. Reasoning over event logs and justifications allows data owners to verify that their privacy policies are being correctly enforced.en_US
dc.description.sponsorshipUnited States. Air Force Office of Scientific Research (Award FA9550-09- 1-0152)en_US
dc.description.sponsorshipUnited States. Intelligence Advanced Research Projects Activity (Award number FA8750-07-2- 0031)en_US
dc.language.isoen_US
dc.publisherIEEE Computer and Reliability Societiesen_US
dc.relation.isversionofhttp://dx.doi.org/10.1109/MSP.2010.89en_US
dc.rightsArticle is made available in accordance with the publisher's policy and may be subject to US copyright law. Please refer to the publisher's site for terms of use.en_US
dc.sourceIEEEen_US
dc.titlePreserving Privacy Based on Semantic Policy Toolsen_US
dc.typeArticleen_US
dc.identifier.citationKagal, Lalana, and Joseph Pato. “Preserving Privacy Based on Semantic Policy Tools.” IEEE Security & Privacy Magazine 8.4 (2010): 25–30. Web.© 2010 IEEE.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratoryen_US
dc.contributor.approverKagal, Lalana S.
dc.contributor.mitauthorKagal, Lalana
dc.relation.journalIEEE Security & Privacy Magazineen_US
dc.eprint.versionFinal published versionen_US
dc.type.urihttp://purl.org/eprint/type/JournalArticleen_US
eprint.statushttp://purl.org/eprint/status/PeerRevieweden_US
dspace.orderedauthorsKagal, Lalana; Pato, Josephen
mit.licensePUBLISHER_POLICYen_US
mit.metadata.statusComplete


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record