Credential purpose-based access control for personal data protection in web-based applications

Web-based applications enable users to carry out their business transactions virtually at any time and place whereby users are required to disclose almost all their personal information which result in greater risks of information disclosure. Therefore, protecting personal information is of utmost i...

Full description

Bibliographic Details
Main Author: Abdul Ghani, Norjihan (Author)
Format: Thesis
Published: 2013-04.
Subjects:
Online Access:Get fulltext
LEADER 02411 am a22001573u 4500
001 34597
042 |a dc 
100 1 0 |a Abdul Ghani, Norjihan  |e author 
245 0 0 |a Credential purpose-based access control for personal data protection in web-based applications 
260 |c 2013-04. 
520 |a Web-based applications enable users to carry out their business transactions virtually at any time and place whereby users are required to disclose almost all their personal information which result in greater risks of information disclosure. Therefore, protecting personal information is of utmost importance. Enforcing personal information protection in databases requires controlled access to systems and resources and granted only to authorized users. Traditional access control systems cannot be used in achieving full personal data protection. Current purposebased access control systems provide insufficient protection of personal data especially in web-based applications. This is mainly due to the absence of user authentication in these systems and the fact that data subjects have less control over their information. This research is an effort to overcome this problem in which the Credential Purpose-Based Access Control (CrePBAC) system is introduced. This system implements a two-phase security and an access control mechanism with a model and security policy implementation. The two-phase security model involves user authentication using personal credential and data authorization based on purpose. The organization's security and privacy policies are implemented using metadata technique in Hippocratic Databases. The metadata technique utilizes a data labeling scheme based on purpose and control data access through query modification. The model and mechanism were successfully implemented. The results from the two types of case studies tested showed that the access control mechanism provides users with more rights and control over their data. In conclusion, this research has introduced a new approach in purpose-based access control with a two-phase security model and mechanism that provides greater control for personal data protection in web-based applications. 
546 |a en 
650 0 4 |a QA75 Electronic computers. Computer science 
655 7 |a Thesis 
787 0 |n http://eprints.utm.my/id/eprint/34597/ 
856 |z Get fulltext  |u http://eprints.utm.my/id/eprint/34597/5/NorjihanAbdulGhaniPFSKSM2013.pdf