Skip to main content
QUICK REVIEW

[논문 리뷰] Personal Information Databases

Sabah Al‐Fedaghi, Bernhard Thalheim|ArXiv.org|2009. 09. 23.
Data Quality and Management참고 문헌 11인용 수 4
한 줄 요약

이 논문은 개인식별정보(PII)를 비개인정보(NII)와 명시적으로 구분하는 형식화된 인포니(Infons)를 통해 개인식별정보(PII)를 관리하기 위한 전용 데이터베이스 모델을 제안한다. 이는 개념적 프레임워크와 PII 영역에만 집중된 물리적 데이터베이스 설계를 제공함으로써, PII/NII의 구분에 기반한 맞춤형 관리, 정책 이행 및 기술적 통제를 통해 개인정보 보호 및 보안을 향상시킨다.

ABSTRACT

One of the most important aspects of security organization is to establish a framework to identify security significant points where policies and procedures are declared. The (information) security infrastructure comprises entities, processes, and technology. All are participants in handling information, which is the item that needs to be protected. Privacy and security information technology is a critical and unmet need in the management of personal information. This paper proposes concepts and technologies for management of personal information. Two different types of information can be distinguished: personal information and nonpersonal information. Personal information can be either personal identifiable information (PII), or nonidentifiable information (NII). Security, policy, and technical requirements can be based on this distinction. At the conceptual level, PII is defined and formalized by propositions over infons (discrete pieces of information) that specify transformations in PII and NII. PII is categorized into simple infons that reflect the proprietor s aspects, relationships with objects, and relationships with other proprietors. The proprietor is the identified person about whom the information is communicated. The paper proposes a database organization that focuses on the PII spheres of proprietors. At the design level, the paper describes databases of personal identifiable information built exclusively for this type of information, with their own conceptual scheme, system management, and physical structure.

연구 동기 및 목표

  • 개인정보 관리에서 충족되지 않은 개인정보 보호 및 보안 요구사항을 해결하기 위해.
  • 개념 수준에서 개인식별정보(PII)와 비식별정보(NII)의 구분을 형식화하기 위해.
  • 개인식별정보(PII) 영역에만 전적으로 집중된 전용 데이터베이스 조직을 개발하기 위해.
  • PII 데이터베이스에 맞춤형으로 설계된 개념 체계, 시스템 관리 및 물리적 구조를 수립하기 위해.
  • PII 및 NII의 변환을 나타내는 인포니에 기반한 형식적 제안을 통해 보안 및 정책 요구사항을 지원하기 위해.

제안 방법

  • 개인식별정보(PII)를 개인 데이터의 변환을 나타내는 인포니에 기반한 명제로 정의한다.
  • 소유자의 특성, 대상에 대한 관계, 다른 소유자들과의 관계를 반영하는 단순 인포니로 PII를 분류한다.
  • 일반 목적 데이터베이스와 독립적인 PII 전용 개념적 데이터베이스 체계를 설계한다.
  • PII 관리 및 액세스 제어에 최적화된 전용 물리적 데이터베이스 구조를 구현한다.
  • 인포니를 기반으로 한 형식 모델을 사용하여 데이터 변환을 표현하고 관리하면서 개인정보 보호를 유지한다.
  • 개념적, 논리적, 물리적 수준에서 PII와 NII를 분리하여 별도의 보안 및 정책 메커니즘을 지원한다.

실험 결과

연구 질문

  • RQ1데이터베이스 환경에서 개인식별정보(PII)와 비식별정보(NII)를 어떻게 형식적으로 구분할 수 있는가?
  • RQ2인포니와 그 변환을 통해 보안적이고 개인정보 보호 중심의 PII 관리가 가능한 개념적 프레임워크는 무엇인가?
  • RQ3개념 체계, 관리 및 물리적 구조를 자체적으로 가진 PII 전용 데이터베이스 시스템은 어떻게 설계할 수 있는가?
  • RQ4PII/NII의 구분으로부터 유도할 수 있는 기술적 및 정책적 메커니즘은 무엇이며, 이를 통해 정보 보안을 어떻게 향상시킬 수 있는가?
  • RQ5소유자의 역할과 관계는 PII 중심의 데이터베이스 아키텍처 내에서 어떻게 모델링할 수 있는가?

주요 결과

  • 논문은 인포니에 기반한 명제를 통해 PII와 NII를 성공적으로 형식화하여 데이터 변환의 정밀한 모델링을 가능하게 하였다.
  • 일반 목적 데이터베이스와 구별되는 전용 개념적 및 물리적 데이터베이스 설계가 제안되었으며, 이는 보안 및 개인정보 보호를 향상시켰다.
  • 모든 설계 수준에서 PII와 NII를 명시적으로 구분함으로써 정책 및 기술적 요구사항을 지원하는 모델이 구현되었다.
  • 프레임워크는 단순 인포니를 통해 소유자의 특성, 대상에 대한 관계, 그리고 상호관계를 표현할 수 있다.
  • 형식적 데이터 분류에 기반한 개인정보 보호 중심의 액세스 제어 및 데이터 거버넌스 정책을 구현하기 위한 기반을 제공한다.
  • 제안된 시스템은 IEEE 형식으로 구현되었으며, 국제정보보안학회지(IJCSIS)에 게재되어 학술적 및 기술적 관련성을 입증하였다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.