privacy & semantics

0 downloads 231 Views 2MB Size Report
fabien, gandon, http://fabien.info @fabien_gandon ... authorized information. Pre-check ... DOUBLE EDGED SEMANTICS IN SE
priv cy & sem ntics − why should we care?... − because if we don’t care the semantic Web will never reach its full potential!

fabien, gandon, http://fabien.info

@fabien_gandon

ISWC… 2003…

OWL Meta-model in CLIPS

[Gandon & Sadeh]

Ontology in OWL

&

Ontology stylesheet

Ontology in CLIPS

Annotation in OWL

&

Annotation stylesheet

Annotation in CLIPS

privacy service

query

Rule in (R)OWL

&

Rule stylesheet

Rule in CLIPS

Core Knowledge

answer

Services in (W)OWL

&

Service stylesheet

Service rule in CLIPS

Privacy in (S)OWL

&

Privacy stylesheet

Privacy rule in CLIPS

Query in (Q)OWL

&

Query stylesheet

Query rules in CLIPS XSLT Engine

Query

Query context assertion

Asserting elementary needs for authorized information

Result in OWL JESS

Pre-check access rights

eResult

Assertion of authorized knowledge

Application of obfuscation rules

Post-check access rights

Fetch useful static knowledge Call relevant external services

socio-semantic access control [ECAI 2012, ESWC 2013] S4AC + SHI3LD User

e.g. only my colleagues working on the same subject ASK{ ?res dcterms:creator ?prov . ?prov rel:hasColleague ?user . ?prov foaf:interestedBy ?topic . ?user foaf:interestedBy ?topic }

DOUBLE EDGED expressive policies

extensible vocs factorized rules robust conditions

SEMANTICS IN SECURITY

DOUBLE EDGED

SEMANTICS IN SECURITY

expressive policies

unwanted conclusions

extensible vocs

de-anonymizing

factorized rules

additional complexity completeness & trust

robust conditions semantic divide

security on every floor

standard frameworks & models certified code, protocols… infrastructures, third parties

basic security APIs

programming the semantic web

security on every floor

more than technical

awareness

sustained attention

ergonomics

context changes social engineering

more than technical

preferences

my triple statement…

(semantics are a double-edged weapon for security, deployment requires security on every floor, security is much more than a technical problem)

my triple statement…

(semantics are a double-edged weapon for security, deployment requires security on every floor, security is much more than a technical problem)

but there will be leaks beyond prevention: monitoring, tracing, detecting, chasing, licensing,… fabien, gandon, http://fabien.info

@fabien_gandon