Proceedings of the IEEE International Symposium on Policies for Distributed Systems and Networks

A Policy Based Infrastructure for Social Data Access with Privacy Guarantees

and

In this paper, we present a policy based infrastructure for social data access with the goal of enabling scientific research, while preservingprivacy. We describe motivating application scenarios that could be enabled with the growing number of user datasets such as social networks, medical datasets etc. These datasets contain sensitive user information and sufficient caution must be exercised while sharing them with third parties to prevent privacy leaks. One of the goals of our framework is to allow users to control how their data is used, while at the same time enable researchers to use the aggregate data for scientific research. We extend existing access control languages to explicitly model user intent in data sharing as well as supporting additional access modes viz. Complete Access, Abstract Access and Statistical Access that go beyond the traditional allow/deny binary semantics of access control. We then describe our policy infrastructure and show how it can be used to enable the above scenarios while still guaranteeing individual privacy. We then present our initial implementation of the framework extending the SecPAL authorization language to account for new roles and operations.


  • 566272 bytes

  • 377335 bytes

  • 285128 bytes

  • 797184 bytes

policy, privacy, social media

InProceedings

IEEE Computer Society

Downloads: 3431 downloads

Google Scholar Citations: 6 citations

UMBC ebiquity