Privacy-aware access control with generalization boundaries
Min Li, Hua Wang, Ashley W. Plank · University of Southern Queensland ePrints (University of Southern Queensland) · 2009
Privacy is today an important concern for both data providers and data users. Data generalization can provide significant protection of an individual’s pri-vacy, which means the data value can be replaced by a less specific but semantically consistent value and the personal information can be collected in a gen-eralized form. However, over-generalized data may render data of little value. A key question is whether or not a certain generalization strategy provides a suf-ficient level of privacy and usability? In this paper, we introduce a new approach, called privacy-aware generalization boundaries, which can satisfy the requirements of both data providers and data users. We propose a privacy-aware access con-trol model related to a retention period. Formal def-initions of authorization actions and rules are pre-sented. Further, we discuss how to manage a valid access process and analysis the access control policy. Finally, we extend our model to support highly com-plex privacy-related policies by taking into account features of obligations and conditions. 1