Towards Accountable Management of Identity and Privacy: Sticky Policies and Enforceable Tracing Services

  • Authors:
  • Marco Casassa Mont;Siani Pearson;Pete Bramhall

  • Affiliations:
  • -;-;-

  • Venue:
  • DEXA '03 Proceedings of the 14th International Workshop on Database and Expert Systems Applications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Digital identities and profiles are precious assets. Onone hand they enable users to engage in transactions andinteractions on the Internet. On the other hand, abusesand leakages of this information could violate the privacyof their owners, sometimes with serious consequences.Nowadays most of the people have limitedunderstanding of security and privacy policies whenapplied to their confidential information and little controlover the destiny of this information once it has beendisclosed to third parties. In most cases this is a matter oftrust.This document describes an innovative approach andrelated mechanisms to enforce users' privacy by puttingusers in control and making organizations moreaccountable. As part of our ongoing research activity, weintroduce a technical solution based on sticky policiesand tracing services that leverages Identifier-basedEncryption (IBE) and TCPA technologies. Work is inprogress to build a full working prototype and deploy it ina real-life environment.