Consent validation for personal data access control using ABAC

  • Maria Molina Universidad de la Republica Oriental del Uruguay
  • Gustavo Betarte Universidad de la Republica Oriental del Uruguay
  • Carlos Luna Universidad de la Republica Oriental del Uruguay

Resumo


To comply with personal data protection regulations, systems that handle personal data must ensure that they verify users’ consent to use their information for a specific purpose. Validating consent is not a simple task, as the purpose typically begins with a high-level definition that needs to be interpreted and modeled accurately for proper evaluation and validation. In this work, we examine the issues associated with consent validation and investigate the effectiveness of attribute-based access control (ABAC) mechanisms in addressing this challenge. Based on this analysis, we propose an ABAC-based approach to verify the information owner’s consent and the user’s access permissions when requesting access. We illustrate this approach with an experiment we have conducted on a well-known benchmark for access control mechanisms defined by NIST, showing how validation rules based on the proposed approach can be implemented.
Palavras-chave: Security, data protection regulations, consent validation, ABAC
Publicado
26/11/2024
MOLINA, Maria; BETARTE, Gustavo; LUNA, Carlos. Consent validation for personal data access control using ABAC. In: FAST ABSTRACT - LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING (LADC), 13. , 2024, Recife/PE. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2024 . p. 30–31.