You are here: Resources > FIDIS Deliverables > Privacy and legal-social content > D14.3: Study on the Suitability of Trusted Computing to support Privacy in Business Processes > 
Trust in Enforcement of Privacy Statements  Title:
EXTENDING THE ONE-SIDED TRUST MODEL
 How to read this Deliverable

 

Extending the one-sided Trust Model

The objective of this deliverable is to extend the one-sided trust model so that users need not to trust service providers regarding the enforcement of the agreed rules. Users should be able to verify whether these rules have been enforced (cf. ). Since obligations cannot be enforced by the access control mechanism deployed at the user (Pretscher, Hilty and Basin, 2006), e.g. identity management systems of type 3 (Bauer, Meints and Hansen, 2005), but observed, this study focuses on monitoring the usage of personal data according the agreed obligations. It has to be assured that such a monitor is deployed at the information system of the corresponding service provider. A widespread approach of the industry for giving such an attestation is Trusted Computing, e.g. as it is defined by the specification of the Trusted Computing Group (TCG) (Trusted Computing Group, 2003b).

 


Figure Service providers show their trustworthiness.

 

Trust in Enforcement of Privacy Statements  fidis_wp14_d14.3_v1.0.sxw  How to read this Deliverable
5 / 39