Unification in Privacy Policy Evaluation - Translating EPAL into Prolog

  • Authors:
  • Affiliations:
  • Venue:
  • POLICY '04 Proceedings of the Fifth IEEE International Workshop on Policies for Distributed Systems and Networks
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Privacy policy evaluation engines enable querieswhether a specific user is allowed to access specific datafor a specific purpose. While tools for authoring, maintaining,and auditing privacy policies already exist, no tool existsyet to deal with unification within such policies, e.g., toenable queries if data might be modified by some user, orhow many user entries satisfy a certain constraint. We showhow this can can be achieved by embedding enterprise privacypolicies into Prolog. We show this concretely for IBM'sEnterprise Privacy Authorization Language (EPAL). Basedon the unification mechanisms of Prolog, our work enablesgeneral queries for privacy policies as well as quantitativemeasurements.