Skip to main navigation Skip to search Skip to main content

A Semi-Automated Methodology for Extracting Access Control Rules from the European Data Protection Directive

  • Kaniz Fatema
  • , Christophe Debruyne
  • , Dave Lewis
  • , Declan Osullivan
  • , John P. Morrison
  • , Abdullah Al Mazed
  • Trinity College Dublin
  • Next Gen Security

Research output: Chapter in Book/Report/Conference proceedingsConference proceedingpeer-review

Abstract

Handling personal data in a legally compliant way is an important factor for ensuring the trustworthiness of a service provider. The EU data protection directive (EU DPD) is built in such a way that the outcomes of rules are subject to explanations, contexts with dependencies, and human interpretation. Therefore, the process of obtaining deterministic and formal rules in policy languages from the EU DPD is difficult to fully automate. To tackle this problem, we demonstrate in this paper the use of a Controlled Natural Language (CNL) to encode the rules of the EU DPD, in a manner that can be automatically converted into the policy languages XACML and PERMIS. We also show that forming machine executable rules automatically from the controlled natural language grammar not only has the benefit of ensuring the correctness of those rules but also has potential of making the overall process more efficient.

Original languageEnglish
Title of host publicationProceedings - 2016 IEEE Symposium on Security and Privacy Workshops, SPW 2016
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages25-32
Number of pages8
ISBN (Electronic)9781509008247
DOIs
Publication statusPublished - 1 Aug 2016
Event2016 IEEE Symposium on Security and Privacy Workshops, SPW 2016 - San Jose, United States
Duration: 23 May 201625 May 2016

Publication series

NameProceedings - 2016 IEEE Symposium on Security and Privacy Workshops, SPW 2016

Conference

Conference2016 IEEE Symposium on Security and Privacy Workshops, SPW 2016
Country/TerritoryUnited States
CitySan Jose
Period23/05/1625/05/16

Keywords

  • Access Control
  • Conflict Resolution
  • Controlled Natural Language
  • EU Data Protection Directive
  • Legal PDP
  • Rules

Fingerprint

Dive into the research topics of 'A Semi-Automated Methodology for Extracting Access Control Rules from the European Data Protection Directive'. Together they form a unique fingerprint.

Cite this