Publication:
Privacy policies verification in composite services using OWL

dc.contributor.authorAssadarat Khuraten_US
dc.contributor.authorBoontawee Suntisrivarapornen_US
dc.contributor.authorDieter Gollmannen_US
dc.contributor.otherHamburg University of Technologyen_US
dc.contributor.otherMahidol Universityen_US
dc.contributor.otherThammasat Universityen_US
dc.contributor.otherMarketing Groupen_US
dc.date.accessioned2018-12-21T07:20:16Z
dc.date.accessioned2019-03-14T08:03:25Z
dc.date.available2018-12-21T07:20:16Z
dc.date.available2019-03-14T08:03:25Z
dc.date.issued2017-06-01en_US
dc.description.abstract© 2017 Elsevier Ltd Privacy has been an important issue for online services collecting customer data. P3P is a privacy policy language with a fixed vocabulary to express privacy practices of online services. The matching between the privacy practices (P3P policies) and users’ privacy preferences facilitates the users to be aware of services’ usage of their data. However, the change from single to composite online services raises more privacy concern due to the increasing amount of user data being collected, stored and shared. This change impacts on P3P since it was designed from a single service perspective. In addition, P3P allows the specification of policies containing semantic inconsistencies. In this paper, we extend P3P to be suitable for composite services and propose a formal semantics for P3P using OWL to facilitate reasoning about semantic ambiguities in P3P policies. The constraints defined in our ontology are used to verify potential semantic inconsistencies and to check for conflicts occurring from P3P policies of service members. We have implemented a P3P verification tool and verified five hundred P3P policies collected from actual websites. The verification result shows that more than half of these P3P policies contain conflicts.en_US
dc.identifier.citationComputers and Security. Vol.67, (2017), 122-141en_US
dc.identifier.doi10.1016/j.cose.2017.02.015en_US
dc.identifier.issn01674048en_US
dc.identifier.other2-s2.0-85015055566en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/42366
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85015055566&origin=inwarden_US
dc.subjectComputer Scienceen_US
dc.titlePrivacy policies verification in composite services using OWLen_US
dc.typeArticleen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85015055566&origin=inwarden_US

Files

Collections