Title
A Semi-Automated Methodology for Extracting Access Control Rules from the European Data Protection Directive
Abstract
Handling personal data in a legally compliant way is an important factor for ensuring the trustworthiness of a service provider. The EU data protection directive (EU DPD) is built in such a way that the outcomes of rules are subject to explanations, contexts with dependencies, and human interpretation. Therefore, the process of obtaining deterministic and formal rules in policy languages from the EU DPD is difficult to fully automate. To tackle this problem, we demonstrate in this paper the use of a Controlled Natural Language (CNL) to encode the rules of the EU DPD, in a manner that can be automatically converted into the policy languages XACML and PERMIS. We also show that forming machine executable rules automatically from the controlled natural language grammar not only has the benefit of ensuring the correctness of those rules but also has potential of making the overall process more efficient.
Year
DOI
Venue
2016
10.1109/SPW.2016.16
2016 IEEE Security and Privacy Workshops (SPW)
Keywords
Field
DocType
Legal PDP,Access Control,Rules,Conflict Resolution,EU Data Protection Directive,Controlled Natural Language
Controlled natural language,Computer security,Computer science,Correctness,Data Protection Directive,XACML,Natural language,PERMIS,Information privacy,Executable
Conference
ISBN
Citations 
PageRank 
978-1-5090-3691-2
3
0.42
References 
Authors
17
6
Name
Order
Citations
PageRank
Kaniz Fatema111310.47
Christophe Debruyne29927.83
Dave Lewis330.75
Declan O'Sullivan447169.07
John P. Morrison526245.28
Abdullah-Al Mazed630.42