A privacy controller approach for privacy protection in web services

  • Authors:
  • George O. M. Yee

  • Affiliations:
  • National Research Council Canada, Ottawa, ON, Canada

  • Venue:
  • Proceedings of the 2007 ACM workshop on Secure web services
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

The growth of the Internet has been accompanied by the growth of web services (e.g. e-commerce, e-health). This increased use of web services has meant that more and more user personal information is being shared with web service providers, leading to the need to protect the privacy of web service users, as evidenced by the enactment of privacy legislation in many jurisdictions. Existing privacy policy approaches for privacy protection, such as making the service provider's privacy policy known to the user, or the use of P3P privacy policies, are inadequate. In the former case, the user cannot know for sure whether or not the provider will honor its policy; in the latter case, there is no flexibility for the user to specify her own policy for governing her own personal information - the provider's policy is the only one offered. This paper proposes the use of privacy controllers together with user privacy policies to overcome the limitations in current privacy policy approaches. An example to illustrate the approach is also given.