David H. Lorenz
Open University & Technion
Boaz Rosenan
University of Haifa
A fair privacy policy
Non-intentional privacy leaks
Instead of trusting applications with our data...
We simply do not give applications access to it!
Application Service Provider
Application
Users
User Data
Cloud Service Provider
Platform as a Service (PaaS)
Users
User Data
Application Provider
Application
How can an application work without access to user data?
or
Cloud Service Provider
CloudLog Database
Users
Facts
Application Provider
Rules
CloudLog Database
How can access control be applied without trusting the application?
This is a statement,
not an axiom!
It is going to rain on Wednesday
This is an axiom.
The weatherman told the viewers it was going to rain on Wednesday
A user will see a fact in query results if:
Trusted
Cloud Service Provider
Users
Facts
Application Provider
Rules
or
Unchecked Rule
Checked Rule
Do one Thing and Do it Well.
Douglas McIlroy
}
CloudLog
Application Service Provider
Application
Users
User Data
If you want to keep doing this...
Cloud Service Provider
Platform as a Service (PaaS)
Users
User Data
Application Provider
Application
This is possible!