Crime and Punishment in the Cloud Accountability, Transparency, and - - PowerPoint PPT Presentation

crime and punishment in the cloud
SMART_READER_LITE
LIVE PREVIEW

Crime and Punishment in the Cloud Accountability, Transparency, and - - PowerPoint PPT Presentation

Crime and Punishment in the Cloud Accountability, Transparency, and Privacy Stefan Berthold , Simone Fischer-Hbner, Leonardo A. Martucci, and T obias Pulls Karlstad University Department of Mathematics and Computer Science 651 88 Karlstad,


slide-1
SLIDE 1

Crime and Punishment in the Cloud

Accountability, Transparency, and Privacy Stefan Berthold, Simone Fischer-Hübner, Leonardo A. Martucci, and T

  • bias Pulls

Karlstad University Department of Mathematics and Computer Science 651 88 Karlstad, Sweden

6th June 2013

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 1 / 7

slide-2
SLIDE 2

ISO/IEC 29100

Accountability document policies, procedures and practices, assign the duty to implement privacy policies to specified individuals in the organization, provide suitable training, inform about privacy breaches, give access to effective sanctions and procedures for compensations in case of privacy breaches. Implications accountability ← transparency + liability for privacy + · · · privacy breaches (crime) punishment.

  • Reference. ISO/IEC: Privacy framework.

ISO/IEC 29100, ISO/IEC (2011). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 2 / 7

slide-3
SLIDE 3

ISO/IEC 29100

Accountability document policies, procedures and practices, assign the duty to implement privacy policies to specified individuals in the organization, provide suitable training, inform about privacy breaches, give access to effective sanctions and procedures for compensations in case of privacy breaches. Implications accountability ← transparency + liability for privacy + · · · privacy breaches (crime) punishment.

  • Reference. ISO/IEC: Privacy framework.

ISO/IEC 29100, ISO/IEC (2011). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 2 / 7

slide-4
SLIDE 4

ISO/IEC 29100

Accountability document policies, procedures and practices, assign the duty to implement privacy policies to specified individuals in the organization, provide suitable training, inform about privacy breaches, give access to effective sanctions and procedures for compensations in case of privacy breaches. Implications accountability ← transparency + liability for privacy + · · · privacy breaches (crime) punishment.

  • Reference. ISO/IEC: Privacy framework.

ISO/IEC 29100, ISO/IEC (2011). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 2 / 7

slide-5
SLIDE 5

Privacy & Transparency

privacy

  • accountability

transparency

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 3 / 7

slide-6
SLIDE 6

Privacy & Transparency

privacy

  • accountability

transparency

− +

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 3 / 7

slide-7
SLIDE 7

Privacy & Transparency

privacy

  • accountability

transparency

− +

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 3 / 7

slide-8
SLIDE 8

Privacy & Transparency

privacy

  • accountability

transparency

− +

confidentiality

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 3 / 7

slide-9
SLIDE 9

Privacy & Transparency

privacy

  • accountability

transparency

− +

confidentiality unrestricted data access

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 3 / 7

slide-10
SLIDE 10

Privacy & Transparency

privacy

  • accountability

transparency

− +

confidentiality unrestricted data access

?

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 3 / 7

slide-11
SLIDE 11

Transparency

Transparency of the next move.

rZblkans

  • popZpop

0ZnZ0Z0Z Z0Z0o0Z0 0Z0ZPZ0Z Z0Z0ZNZ0 POPO0OPO SNAQJBZR

Definition

Transparency is the state when every party in the target group possesses perfect knowledge about the

  • bservable of interest. In other

words, no party in the target group could learn any information (in Shannon’s sense) about the

  • bservable of interest.
  • Reference. Shannon, C. E.: A mathematical theory of communications.

Bell System T echnical Journal 27, 379–423, 623–656 (1948). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 4 / 7

slide-12
SLIDE 12

Transparency

Transparency of the next move.

rZblkans

  • popZpop

0ZnZ0Z0Z Z0Z0o0Z0 0Z0ZPZ0Z Z0Z0ZNZ0 POPO0OPO SNAQJBZR

  • knowledge

p

Definition

Transparency is the state when every party in the target group possesses perfect knowledge about the

  • bservable of interest. In other

words, no party in the target group could learn any information (in Shannon’s sense) about the

  • bservable of interest.
  • Reference. Shannon, C. E.: A mathematical theory of communications.

Bell System T echnical Journal 27, 379–423, 623–656 (1948). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 4 / 7

slide-13
SLIDE 13

Transparency

Transparency of the next move.

rZblkans

  • popZpop

0ZnZ0Z0Z Z0Z0o0Z0 0Z0ZPZ0Z Z0Z0ZNZ0 POPO0OPO SNAQJBZR

  • knowledge

p B

Definition

Transparency is the state when every party in the target group possesses perfect knowledge about the

  • bservable of interest. In other

words, no party in the target group could learn any information (in Shannon’s sense) about the

  • bservable of interest.
  • Reference. Shannon, C. E.: A mathematical theory of communications.

Bell System T echnical Journal 27, 379–423, 623–656 (1948). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 4 / 7

slide-14
SLIDE 14

Transparency

Transparency of the next move.

rZblkans

  • popZpop

0ZnZ0Z0Z Z0Z0o0Z0 0Z0ZPZ0Z Z0Z0ZNZ0 POPO0OPO SNAQJBZR

  • knowledge

p B

  • racle

B

information

Definition

Transparency is the state when every party in the target group possesses perfect knowledge about the

  • bservable of interest. In other

words, no party in the target group could learn any information (in Shannon’s sense) about the

  • bservable of interest.
  • Reference. Shannon, C. E.: A mathematical theory of communications.

Bell System T echnical Journal 27, 379–423, 623–656 (1948). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 4 / 7

slide-15
SLIDE 15

Transparency

Transparency of the next move.

rZblkans

  • popZpop

0ZnZ0Z0Z Z0Z0o0Z0 0Z0ZPZ0Z Z0Z0ZNZ0 POPO0OPO SNAQJBZR

B

knowledge

B B

  • racle

B

zero information

Definition

Transparency is the state when every party in the target group possesses perfect knowledge about the

  • bservable of interest. In other

words, no party in the target group could learn any information (in Shannon’s sense) about the

  • bservable of interest.
  • Reference. Shannon, C. E.: A mathematical theory of communications.

Bell System T echnical Journal 27, 379–423, 623–656 (1948). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 4 / 7

slide-16
SLIDE 16

Transparency

Transparency of the next move.

rZblkans

  • popZpop

0ZnZ0Z0Z ZBZ0o0Z0 0Z0ZPZ0Z Z0Z0ZNZ0 POPO0OPO SNAQJ0ZR

B

knowledge

B B

  • racle

B

zero information

Definition

Transparency is the state when every party in the target group possesses perfect knowledge about the

  • bservable of interest. In other

words, no party in the target group could learn any information (in Shannon’s sense) about the

  • bservable of interest.
  • Reference. Shannon, C. E.: A mathematical theory of communications.

Bell System T echnical Journal 27, 379–423, 623–656 (1948). stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 4 / 7

slide-17
SLIDE 17

Privacy

user CSP 1 CSP 2 CSP n

  • p. data
  • p. data
  • p. data

· · · · · · · · · · · · · · · · · · · · · · · · · · ·

CSP 1 CSP 2 CSP 3

PIA PIA PIA

subcontracting subcontracting dependency resolution dependency resolution

Definition

Privacy is the right of individuals to control the flow and use of their personal data. requires informed decisions about data disclosure, data storage, and data processing, and their enforcement.

  • Reference. EU: Data Protecting Directive 95/46/EC.

. stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 5 / 7

slide-18
SLIDE 18

Conclusions

Accountability for end-users.

Definition

A data controller is accountable, if privacy breaches are transparent to the respective data subjects and the data controller is sanctioned and/or the data subject is compensated in case of privacy breaches. Challenges. accountability: composing privacy and transparency. the cloud doesn’t make that challenge easier. solutions exist for accountability where privacy is end-user control. hard conflicts between transparency and privacy when privacy is confidentiality.

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 6 / 7

slide-19
SLIDE 19

Conclusions

Accountability for end-users.

Definition

A data controller is accountable, if privacy breaches are transparent to the respective data subjects and the data controller is sanctioned and/or the data subject is compensated in case of privacy breaches. Challenges. accountability: composing privacy and transparency. the cloud doesn’t make that challenge easier. solutions exist for accountability where privacy is end-user control. hard conflicts between transparency and privacy when privacy is confidentiality.

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 6 / 7

slide-20
SLIDE 20

Crime and Punishment in the Cloud

Q&A

Stefan Berthold, Simone Fischer-Hübner, Leonardo A. Martucci, and T

  • bias Pulls

[firstname.lastname]@kau.se

stefan berthold <stefan.berthold@kau.se> crime and punishment in the cloud tafc workshop, málaga, spain, 6th june 2013 7 / 7