Consent validation for personal data access control using ABAC
Resumo
To comply with personal data protection regulations, systems that handle personal data must ensure that they verify users’ consent to use their information for a specific purpose. Validating consent is not a simple task, as the purpose typically begins with a high-level definition that needs to be interpreted and modeled accurately for proper evaluation and validation. In this work, we examine the issues associated with consent validation and investigate the effectiveness of attribute-based access control (ABAC) mechanisms in addressing this challenge. Based on this analysis, we propose an ABAC-based approach to verify the information owner’s consent and the user’s access permissions when requesting access. We illustrate this approach with an experiment we have conducted on a well-known benchmark for access control mechanisms defined by NIST, showing how validation rules based on the proposed approach can be implemented.
Palavras-chave:
Security, data protection regulations, consent validation, ABAC
Publicado
26/11/2024
Como Citar
MOLINA, Maria; BETARTE, Gustavo; LUNA, Carlos.
Consent validation for personal data access control using ABAC. In: FAST ABSTRACT - LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING (LADC), 13. , 2024, Recife/PE.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2024
.
p. 30–31.
