Extending XACML access control architecture for allowing preference-based authorisation

  • Authors:
  • Gina Kounga;Marco Casassa Mont;Pete Bramhall

  • Affiliations:
  • Hewlett-Packard Laboratories, Bristol, United Kingdom;Hewlett-Packard Laboratories, Bristol, United Kingdom;Hewlett-Packard Laboratories, Bristol, United Kingdom

  • Venue:
  • TrustBus'10 Proceedings of the 7th international conference on Trust, privacy and security in digital business
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

European data protection regulation states that organisations must have data subjects' consent to use their personally identifiable information (PII) for a variety of purposes. Solutions have been proposed which generally handle consent in a coarse-grained way, by means of opt in/out choices. However, we believe that consent's representation should be extended to allow data subjects to express a rich set of conditions under which their PII can be used. In this paper we introduce and discuss an approach enabling the representation of consent as fine-grained preferences. To enforce such consent, we leverage and extend the current standard XACML architecture and framework. As data collectors maintain links between PII and associated preferences, preferences should also be considered as part of this PII. Therefore our solution prevents access control components from directly accessing any PII.