Towards pii-based multiparty access control for photo sharing in online social networks
Proceedings of the 22nd ACM on Symposium on Access Control Models and …, 2017•dl.acm.org
The privacy control models of current Online Social Networks (OSNs) are biased towards the
content owners' policy settings. Additionally, those privacy policy settings are too coarse-
grained to allow users to control access to individual portions of information that is related to
them. Especially, in a shared photo in OSNs, there can exist multiple Personally Identifiable
Information (PII) items belonging to a user appearing in the photo, which can compromise
the privacy of the user if viewed by others. However, current OSNs do not provide users any …
content owners' policy settings. Additionally, those privacy policy settings are too coarse-
grained to allow users to control access to individual portions of information that is related to
them. Especially, in a shared photo in OSNs, there can exist multiple Personally Identifiable
Information (PII) items belonging to a user appearing in the photo, which can compromise
the privacy of the user if viewed by others. However, current OSNs do not provide users any …
The privacy control models of current Online Social Networks (OSNs) are biased towards the content owners' policy settings. Additionally, those privacy policy settings are too coarse-grained to allow users to control access to individual portions of information that is related to them. Especially, in a shared photo in OSNs, there can exist multiple Personally Identifiable Information (PII) items belonging to a user appearing in the photo, which can compromise the privacy of the user if viewed by others. However, current OSNs do not provide users any means to control access to their individual PII items. As a result, there exists a gap between the level of control that current OSNs can provide to their users and the privacy expectations of the users. In this paper, we propose an approach to facilitate collaborative control of individual PII items for photo sharing over OSNs, where we shift our focus from entire photo level control to the control of individual PII items within shared photos. We formulate a PII-based multiparty access control model to fulfill the need for collaborative access control of PII items, along with a policy specification scheme and a policy enforcement mechanism. We also discuss a proof-of-concept prototype of our approach as part of an application in Facebook and provide system evaluation and usability study of our methodology.
ACM Digital Library