کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
435236 1441710 2012 12 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Refinement checking for privacy policies
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر نظریه محاسباتی و ریاضیات
پیش نمایش صفحه اول مقاله
Refinement checking for privacy policies
چکیده انگلیسی

This paper presents a framework for analysis and comparison of privacy policies expressed in P3P (Platform for Privacy Preferences). In contrast to existing approaches to policy analysis, which focus on demonstrations of equality or equivalence of policies, our approach makes it possible to check for refinement between policies. We automatically generate a CSP model from a P3P policy, which represents the policy’s intended semantics; using the FDR model checker, we then perform various tests (using process refinement) to determine (a) whether a policy is internally consistent, and (b) whether a given policy refines another by permitting similar data collection, processing and sharing practices. Our approach allows for the detection of subtle differences between practices prescribed by different privacy policies, the comparison of relative levels of privacy offered by different policies, and captures the semantics of policies intended in the original P3P standard. The systematic translation of policies to CSP provides a formal means of reasoning about websites’ privacy policies, and therefore the practices of various enterprises with regards to personal data.


► We propose a process algebraic model of privacy policies.
► We use the CSP modelling language to describe P3P policies and the FDR model checker to check refinements between them.
► The advantage of our approach is that it enables the comparison of policies for refinements, rather than for equality or equivalence.
► We demonstrate our technique using an example of policy comparison.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Science of Computer Programming - Volume 77, Issues 10–11, 1 September 2012, Pages 1198–1209
نویسندگان
, , ,