Skip to main content
QUICK REVIEW

[论文解读] Personal Information Databases

Sabah Al‐Fedaghi, Bernhard Thalheim|ArXiv.org|Sep 23, 2009
Data Quality and Management参考文献 11被引用 4
一句话总结

本文提出一种专门用于管理个人身份信息(PII)的数据库模型,通过形式化的信息单元(infons)区分PII与非个人身份信息(NII)。该研究引入一个概念框架及专用于PII领域的物理数据库设计,通过基于PII/NII区分的定制化管理、策略实施与技术控制,显著提升隐私与安全性。

ABSTRACT

One of the most important aspects of security organization is to establish a framework to identify security significant points where policies and procedures are declared. The (information) security infrastructure comprises entities, processes, and technology. All are participants in handling information, which is the item that needs to be protected. Privacy and security information technology is a critical and unmet need in the management of personal information. This paper proposes concepts and technologies for management of personal information. Two different types of information can be distinguished: personal information and nonpersonal information. Personal information can be either personal identifiable information (PII), or nonidentifiable information (NII). Security, policy, and technical requirements can be based on this distinction. At the conceptual level, PII is defined and formalized by propositions over infons (discrete pieces of information) that specify transformations in PII and NII. PII is categorized into simple infons that reflect the proprietor s aspects, relationships with objects, and relationships with other proprietors. The proprietor is the identified person about whom the information is communicated. The paper proposes a database organization that focuses on the PII spheres of proprietors. At the design level, the paper describes databases of personal identifiable information built exclusively for this type of information, with their own conceptual scheme, system management, and physical structure.

研究动机与目标

  • 解决个人身份信息管理中尚未满足的隐私与安全需求。
  • 在概念层面对个人身份信息(PII)与非身份识别信息(NII)的区分进行形式化。
  • 开发一个专用于PII领域的数据库组织结构,以提升安全性和策略执行能力。
  • 建立一个针对PII数据库量身定制的概念方案、系统管理与物理结构。
  • 通过基于infons的正式命题,支持对PII与NII中数据变换的隐私与策略需求。

提出的方法

  • 通过infons上的命题定义PII——即表示个人数据变换的离散信息单元。
  • 将PII分类为反映所有者特征、与对象关系以及与其他所有者关系的简单infons。
  • 设计一个专用于PII的概念数据库方案,独立于通用数据库。
  • 实现一个专用于PII管理与访问控制的物理数据库结构。
  • 基于infons的正式模型,表示并管理数据变换,同时保护隐私。
  • 在概念、逻辑与物理层面分离PII与NII,以支持不同的安全与策略机制。

实验结果

研究问题

  • RQ1在数据库环境中,如何对个人身份信息(PII)与非身份识别信息(NII)进行形式化区分?
  • RQ2何种概念框架能够通过infons及其变换实现PII的安全且保护隐私的管理?
  • RQ3如何设计一个专用于PII的数据库系统,具备独立的概念方案、管理机制与物理结构?
  • RQ4可以从PII/NII区分中推导出哪些技术与策略机制,以提升信息安全?
  • RQ5如何在以PII为中心的数据库架构中建模所有者的角色及其相互关系?

主要发现

  • 本文成功通过infons上的命题形式化了PII与NII,实现了对数据变换的精确建模。
  • 提出了一套专用于PII的概念与物理数据库设计,与通用数据库相分离,显著提升了安全与隐私保护。
  • 该模型通过在所有设计层级明确区分PII与NII,支持策略与技术需求。
  • 该框架能够通过简单infons表示所有者的特征、与对象的关系以及人与人之间的关系。
  • 该方法为基于正式数据分类的隐私保护访问控制与数据治理策略的实施提供了基础。
  • 所提出的系统以IEEE格式实现,并发表于《国际计算机科学与信息安全管理杂志》(IJCSIS),验证了其学术与技术相关性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。