Skip to main content
QUICK REVIEW

[Paper Review] Security and Privacy Policy Languages: A Survey, Categorization and Gap Identification

Saffija Kasem-Madani, Michael Meier|arXiv (Cornell University)|Dec 1, 2015
Access Control and Trust17 references19 citations
TL;DR

This paper presents a comprehensive survey and categorization framework for 27 security and privacy policy languages, identifying a critical gap in existing languages: none adequately support the specification of privacy-utility trade-off agreements. The authors propose the need for new policy languages that enable negotiation and enforcement of such trade-offs, especially in data sharing scenarios involving privacy-preserving analytics and encrypted computation.

ABSTRACT

For security and privacy management and enforcement purposes, various policy languages have been presented. We give an overview on 27 security and privacy policy languages and present a categorization framework for policy languages. We show how the current policy languages are represented in the framework and summarize our interpretation. We show up identified gaps and motivate for the adoption of policy languages for the specification of privacy-utility trade-off policies.

Motivation & Objective

  • To survey and analyze 27 existing security and privacy policy languages from the literature.
  • To identify the lack of support for privacy-utility trade-off policies in current language designs.
  • To propose a multidimensional categorization framework for systematic classification of policy languages.
  • To motivate the development of new policy languages that enable negotiation and enforcement of privacy-utility trade-offs in data sharing.
  • To highlight the need for policy-based frameworks to integrate emerging privacy-enhancing technologies like homomorphic encryption.

Proposed method

  • Developed a four-dimensional categorization framework based on Type, Intention of Use, Scope, and Design and Implementation Details.
  • Mapped 27 existing policy languages into the framework to analyze their expressiveness and coverage across dimensions.
  • Identified that no language supports the specification of privacy-utility trade-off agreements, especially in data analysis contexts.
  • Proposed a use case involving data holders and analyzers negotiating relaxed privacy constraints for utility in big data analytics.
  • Advocated for integrating policy languages with privacy-enhancing technologies such as homomorphic encryption and credential-based anonymous authorization.
  • Suggested future work on formalizing privacy-risk-aware negotiation policies and enhancing real-world deployment of privacy-utility trade-off mechanisms.

Experimental results

Research questions

  • RQ1What are the key dimensions that can be used to systematically categorize security and privacy policy languages?
  • RQ2Which existing policy languages adequately support privacy-utility trade-off agreements in data sharing?
  • RQ3What are the limitations of current policy languages in expressing and enforcing privacy-utility trade-offs?
  • RQ4How can policy languages be extended to support negotiation and enforcement of privacy-preserving data analysis agreements?
  • RQ5What role can policy-based frameworks play in enabling secure, privacy-preserving computation with encrypted data?

Key findings

  • No existing policy language supports the specification of privacy-utility trade-off agreements, despite growing demand in data analytics and privacy-preserving computation.
  • The categorization framework reveals that privacy-utility trade-offs are not addressed in any of the nine types of policy languages analyzed.
  • Current languages lack mechanisms for negotiating the relaxation of privacy constraints in exchange for data utility, especially in third-party data processing.
  • The integration of homomorphic encryption and other privacy-enhancing technologies is not yet supported by policy languages, creating a deployment gap.
  • Negotiation mechanisms for privacy-preserving data sharing are absent, even though credential-based anonymous authorization exists in isolated systems.
  • There is a clear need for policy languages that formalize application-specific privacy-risk trade-offs and support automated enforcement of such agreements.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.