Skip to main content
QUICK REVIEW

[論文レビュー] Personal Information Databases

Sabah Al‐Fedaghi, Bernhard Thalheim|ArXiv.org|Sep 23, 2009
Data Quality and Management参考文献 11被引用数 4
ひとこと要約

本論文は、個人識別情報(PII)と非個人情報(NII)を形式化されたinfonsを用いて区別することにより、PIIを管理する専用のデータベースモデルを提案する。形式的な枠組みとPIIに特化した物理的データベース設計を提示し、PII/NIIの区別に基づく特化された管理、ポリシーの強制、技術的制御を通じて、プライバシーとセキュリティの向上を実現する。

ABSTRACT

One of the most important aspects of security organization is to establish a framework to identify security significant points where policies and procedures are declared. The (information) security infrastructure comprises entities, processes, and technology. All are participants in handling information, which is the item that needs to be protected. Privacy and security information technology is a critical and unmet need in the management of personal information. This paper proposes concepts and technologies for management of personal information. Two different types of information can be distinguished: personal information and nonpersonal information. Personal information can be either personal identifiable information (PII), or nonidentifiable information (NII). Security, policy, and technical requirements can be based on this distinction. At the conceptual level, PII is defined and formalized by propositions over infons (discrete pieces of information) that specify transformations in PII and NII. PII is categorized into simple infons that reflect the proprietor s aspects, relationships with objects, and relationships with other proprietors. The proprietor is the identified person about whom the information is communicated. The paper proposes a database organization that focuses on the PII spheres of proprietors. At the design level, the paper describes databases of personal identifiable information built exclusively for this type of information, with their own conceptual scheme, system management, and physical structure.

研究の動機と目的

  • 個人情報管理におけるプライバシーとセキュリティの未解決課題に対処すること。
  • 概念的レベルにおいて、個人識別情報(PII)と非識別情報(NII)の区別を形式化すること。
  • セキュリティとポリシーの強制を向上させるために、PII分野に特化した専用のデータベース組織を構築すること。
  • PIIデータベースに特化した概念的スキーマ、システム管理、物理的構造を確立すること。
  • PIIとNIIの変換を表すinfonsに基づく形式的命題を通じて、セキュリティとポリシー要件を支援すること。

提案手法

  • 個人データの変換を表す離散的な情報単位(infons)に基づくPIIの定義。
  • 所有者に関する側面、対象物との関係、他の所有者との関係を反映する単純なinfonsにPIIを分類すること。
  • 一般用途のデータベースとは独立して、PIIに特化した概念的データベーススキーマの設計。
  • PII管理とアクセス制御に最適化された専用の物理的データベース構造の実装。
  • infonsに基づく形式的モデルを用いて、プライバシーを保持したままデータ変換を表し管理すること。
  • 概念的、論理的、物理的レベルにおいてPIIとNIIを分離し、それぞれに異なるセキュリティおよびポリシーメカニズムをサポートすること。

実験結果

リサーチクエスチョン

  • RQ1データベースの文脈において、個人識別情報(PII)をどのように形式的に非識別情報(NII)から区別できるか。
  • RQ2infonsおよびその変換を通じて、安全でプライバシーを守るPII管理を可能にする概念的枠組みは何か。
  • RQ3独自の概念的スキーマ、管理、物理的構造を持つPII専用データベースシステムをどのように設計できるか。
  • RQ4PII/NIIの区別から導き出せる技術的およびポリシー的メカニズムは何か。これらは情報セキュリティをどのように向上させるか。
  • RQ5所有者の役割と関係は、PII中心のデータベースアーキテクチャ内でどのようにモデル化できるか。

主な発見

  • 本論文は、infonsに基づく命題を用いてPIIとNIIを形式化し、データ変換の正確なモデリングを可能にした。
  • 一般用途のデータベースとは異なる、PIIに特化した概念的および物理的データベース設計が提案され、セキュリティとプライバシーの向上が図られた。
  • 設計のすべてのレベルでPIIとNIIを明示的に区別することにより、ポリシーと技術的要件を支援する。
  • 単純なinfonsを用いて所有者の側面、対象物との関係、人間関係を表現できる。
  • 形式的なデータ分類に基づく、プライバシーを守るアクセス制御とデータガバナンスポリシーの実装の基盤を提供する。
  • 提案されたシステムはIEEEフォーマットで実装され、International Journal of Computer Science and Information Security (IJCSIS) に掲載されており、学術的および技術的妥当性が裏付けられている。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。