Machine-readable privacy certificates for services

Marco Anisetti, Claudio A. Ardagna, Michele Bezzi, Ernesto Damiani, Antonino Sabetta

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Privacy-aware processing of personal data on the web of services requires managing a number of issues arising both from the technical and the legal domain. Several approaches have been proposed to matching privacy requirements (on the clients side) and privacy guarantees (on the service provider side). Still, the assurance of effective data protection (when possible) relies on substantial human effort and exposes organizations to significant (non-)compliance risks. In this paper we put forward the idea that a privacy certification scheme producing and managing machine-readable artifacts in the form of privacy certificates can play an important role towards the solution of this problem. Digital privacy certificates represent the reasons why a privacy property holds for a service and describe the privacy measures supporting it. Also, privacy certificates can be used to automatically select services whose certificates match the client policies (privacy requirements). Our proposal relies on an evolution of the conceptual model developed in the Assert4Soa project and on a certificate format specifically tailored to represent privacy properties. To validate our approach, we present a worked-out instance showing how privacy property Retention-based unlinkability can be certified for a banking financial service.

Original languageBritish English
Title of host publicationOn the Move to Meaningful Internet Systems
Subtitle of host publicationOTM 2013 Conferences - Confederated International Conferences: CoopIS 2013, DOA-Trusted Cloud 2013, and ODBASE 2013, Proceedings
Pages434-450
Number of pages17
DOIs
StatePublished - 2013
EventConfederated International Conferences on On the Move to Meaningful Internet Systems, OTM 2013: CoopIS 2013, DOA-Trusted Cloud 2013, and ODBASE 2013 - Graz, Austria
Duration: 9 Sep 201313 Sep 2013

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8185 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceConfederated International Conferences on On the Move to Meaningful Internet Systems, OTM 2013: CoopIS 2013, DOA-Trusted Cloud 2013, and ODBASE 2013
Country/TerritoryAustria
CityGraz
Period9/09/1313/09/13

Keywords

  • certification
  • privacy
  • testing

Fingerprint

Dive into the research topics of 'Machine-readable privacy certificates for services'. Together they form a unique fingerprint.

Cite this