Privacy Policy Enforcement in Enterprises with Identity
Management Solutions
Marco Casassa Mont, Robert Thyne
1
Trusted Systems Laboratory
HP Laboratories Bristol
HPL-2006-72
April 25, 2006*
privacy, privacy
management,
policy
enforcement,
privacy-aware
access control,
automation,
identity
management
People are usually asked by enterprises and other organizations to
disclose their personal information to access web services and engage in
business interactions. Enterprises need this information to enable their
business processes. This is unlikely to change, at least in the foreseeable
future. When collecting personal data, enterprises must satisfy privacy
laws and policies along with addressing people's expectations on how
their data should be handled. Currently much is done by means of
manual processes, in particular in terms of privacy enforcement: these
processes are prone to mistakes and hard to comply. Automation can help
enterprises to deal with these privacy management issues, in particular
the enforcement of privacy policies on collected personal data.
Enterprises have already been investing in identity management
solutions: they require that approaches to automate privacy management
should keep into account and leverage these solutions. This paper
discusses our research and development work to automate the
enforcement of privacy policies in enterprises. Our model of privacy
policy enforcement is introduced along with the technical details of a
related prototype, integrated (as a proof of concept) with HP Select
Access, a state-of-the-art identity management solution. This technology
is currently under productisation. We discuss our current results and next
steps.
* Internal Accession Date Only
1
Hewlett-Packard, Software Business Organisation, Toronto, Canada
Approved for External Publication
© Copyright 2006 Hewlett-Packard Development Company, L.P.