Conference Publication Details
Mandatory Fields
Kaniz Fatema, Dave Lewis, Declan O'Sullivan, John P Morrison, Abdullah-Al Mazed
2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing (UCC)
Authorising contract based access to personal data in the cloud
2015
December
Published
0
()
Optional Fields
Policy Decision Point (PDP), Contract validation, XACML, EU Data Protection Directive (EU DPD), authorisation systems, Policy Enforcement Point (PEP)
Limassol, Cyprus
The emerging new EU data protection regulation requires that regardless of the location of the data centers a cloud service provider will have to comply with the EU data protection regulation if it provides services to EU citizens. Handling personal data in a legally compliant way is a very important factor for ensuring the trustworthiness of a cloud service provider. In this paper we present a software component called Contract Valida-tion Service (ConVS) that validates digital contracts and helps to automate contract-based access to personal data. The paper then shows how an authorisation system can use the ConVS to auto-mate legally compliant authorisation decisions from XACML formatted EU Data Protection Derivative rules. Such automation in determining contract-based access decisions offers the potential to significantly reduce the effort of ensuring legal compliance of the cloud service providers. Authorising contract based access to personal data in the cloud.
10.1109/UCC.2015.99
Grant Details