Authorising Contract Based Access to Personal Data in the Cloud

  • Kaniz Fatema
  • , Dave Lewis
  • , Declan O'Sullivan
  • , John P. Morrison
  • , Abdullah Al Mazed

Research output: Chapter in Book/Report/Conference proceedingsChapterpeer-review

Abstract

The emerging new EU data protection regulation requires that regardless of the location of the data centers a cloud service provider will have to comply with the EU data protection regulation if it provides services to EU citizens. Handling personal data in a legally compliant way is a very important factor for ensuring the trustworthiness of a cloud service provider. In this paper we present a software component called Contract Validation Service (ConVS) that validates digital contracts and helps to automate contract-based access to personal data. The paper then shows how an authorisation system can use the ConVS to automate legally compliant authorisation decisions from XACML format-ted EU Data Protection Derivative rules. Such automation in determining contract-based access decisions offers the potential to significantly reduce the effort of ensuring legal compliance of the cloud service providers.

Original languageEnglish
Title of host publicationProceedings - 2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing, UCC 2015
EditorsOmer Rana, Rajkumar Buyya, Ioan Raicu
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages559-564
Number of pages6
ISBN (Electronic)9780769556970
DOIs
Publication statusPublished - 2015
Event8th IEEE/ACM International Conference on Utility and Cloud Computing, UCC 2015 - Limassol, Cyprus
Duration: 7 Dec 201510 Dec 2015

Publication series

NameProceedings - 2015 IEEE/ACM 8th International Conference on Utility and Cloud Computing, UCC 2015

Conference

Conference8th IEEE/ACM International Conference on Utility and Cloud Computing, UCC 2015
Country/TerritoryCyprus
CityLimassol
Period7/12/1510/12/15

Keywords

  • authorisation systems
  • Contract validation
  • EU Data Protection Directive (EU DPD)
  • Policy Decision Point (PDP)
  • Policy Enforcement Point (PEP)
  • XACML

Fingerprint

Dive into the research topics of 'Authorising Contract Based Access to Personal Data in the Cloud'. Together they form a unique fingerprint.

Cite this