Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement

In light of the GDPR, data controllers (DC) need to allow data subjects (DS) to exercise certain data subject rights. A key requirement here is that DCs can reliably authenticate a DS. Due to a lack of clear technical specifications, this has been realized in different ways, such as by requesting co...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Hansen, Malte, Büttner, Andre
Format: Buch
Sprache:nor
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator Hansen, Malte
Büttner, Andre
description In light of the GDPR, data controllers (DC) need to allow data subjects (DS) to exercise certain data subject rights. A key requirement here is that DCs can reliably authenticate a DS. Due to a lack of clear technical specifications, this has been realized in different ways, such as by requesting copies of ID documents or by email address verification. However, previous research has shown that this is associated with various security and privacy risks and that identifying DSs can be a non-trivial task. In this paper, we review different authentication schemes and propose an architecture that enables DCs to authenticate DSs with the help of independent Identity Providers in a secure and privacy-preserving manner by utilizing attribute-based credentials and eIDs. Our work contributes to a more standardized and privacy-preserving way of authenticating DSs, which will benefit both DCs and DSs.
format Book
fullrecord <record><control><sourceid>cristin</sourceid><recordid>TN_cdi_cristin_nora_10852_110699</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>10852_110699</sourcerecordid><originalsourceid>FETCH-cristin_nora_10852_1106993</originalsourceid><addsrcrecordid>eNqNitEKgjAUQAcRFLV_uD8gbC5TH6OMHiV7l7WueqUmbFPo7zPoA3o6B85ZMJ6nmRJKJulXVox73wshVCxiJXdrVlZoRoeg7QNKR5M276h06NFNZFs4jKFDG8joQIOFZnBw0kFDNd57NAGu1HbBQ2HnYvA1r1u2bPTTI_9xw-Bc3I6XyDjygWxtB6drKbIkrqUU-zxXfywfeh08nw</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>book</recordtype></control><display><type>book</type><title>Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement</title><source>NORA - Norwegian Open Research Archives</source><source>Springer Books</source><creator>Hansen, Malte ; Büttner, Andre</creator><creatorcontrib>Hansen, Malte ; Büttner, Andre</creatorcontrib><description>In light of the GDPR, data controllers (DC) need to allow data subjects (DS) to exercise certain data subject rights. A key requirement here is that DCs can reliably authenticate a DS. Due to a lack of clear technical specifications, this has been realized in different ways, such as by requesting copies of ID documents or by email address verification. However, previous research has shown that this is associated with various security and privacy risks and that identifying DSs can be a non-trivial task. In this paper, we review different authentication schemes and propose an architecture that enables DCs to authenticate DSs with the help of independent Identity Providers in a secure and privacy-preserving manner by utilizing attribute-based credentials and eIDs. Our work contributes to a more standardized and privacy-preserving way of authenticating DSs, which will benefit both DCs and DSs.</description><identifier>ISBN: 9783031579783</identifier><identifier>ISBN: 303157978X</identifier><language>nor</language><publisher>Springer Nature</publisher><creationdate>2024</creationdate><rights>info:eu-repo/semantics/openAccess</rights><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><link.rule.ids>230,307,776,780,783,881,4034,26544</link.rule.ids></links><search><creatorcontrib>Hansen, Malte</creatorcontrib><creatorcontrib>Büttner, Andre</creatorcontrib><title>Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement</title><description>In light of the GDPR, data controllers (DC) need to allow data subjects (DS) to exercise certain data subject rights. A key requirement here is that DCs can reliably authenticate a DS. Due to a lack of clear technical specifications, this has been realized in different ways, such as by requesting copies of ID documents or by email address verification. However, previous research has shown that this is associated with various security and privacy risks and that identifying DSs can be a non-trivial task. In this paper, we review different authentication schemes and propose an architecture that enables DCs to authenticate DSs with the help of independent Identity Providers in a secure and privacy-preserving manner by utilizing attribute-based credentials and eIDs. Our work contributes to a more standardized and privacy-preserving way of authenticating DSs, which will benefit both DCs and DSs.</description><isbn>9783031579783</isbn><isbn>303157978X</isbn><fulltext>true</fulltext><rsrctype>book</rsrctype><creationdate>2024</creationdate><recordtype>book</recordtype><sourceid>3HK</sourceid><recordid>eNqNitEKgjAUQAcRFLV_uD8gbC5TH6OMHiV7l7WueqUmbFPo7zPoA3o6B85ZMJ6nmRJKJulXVox73wshVCxiJXdrVlZoRoeg7QNKR5M276h06NFNZFs4jKFDG8joQIOFZnBw0kFDNd57NAGu1HbBQ2HnYvA1r1u2bPTTI_9xw-Bc3I6XyDjygWxtB6drKbIkrqUU-zxXfywfeh08nw</recordid><startdate>2024</startdate><enddate>2024</enddate><creator>Hansen, Malte</creator><creator>Büttner, Andre</creator><general>Springer Nature</general><scope>3HK</scope></search><sort><creationdate>2024</creationdate><title>Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement</title><author>Hansen, Malte ; Büttner, Andre</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-cristin_nora_10852_1106993</frbrgroupid><rsrctype>books</rsrctype><prefilter>books</prefilter><language>nor</language><creationdate>2024</creationdate><toplevel>online_resources</toplevel><creatorcontrib>Hansen, Malte</creatorcontrib><creatorcontrib>Büttner, Andre</creatorcontrib><collection>NORA - Norwegian Open Research Archives</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext</fulltext></delivery><addata><au>Hansen, Malte</au><au>Büttner, Andre</au><format>book</format><genre>book</genre><ristype>BOOK</ristype><btitle>Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement</btitle><date>2024</date><risdate>2024</risdate><isbn>9783031579783</isbn><isbn>303157978X</isbn><abstract>In light of the GDPR, data controllers (DC) need to allow data subjects (DS) to exercise certain data subject rights. A key requirement here is that DCs can reliably authenticate a DS. Due to a lack of clear technical specifications, this has been realized in different ways, such as by requesting copies of ID documents or by email address verification. However, previous research has shown that this is associated with various security and privacy risks and that identifying DSs can be a non-trivial task. In this paper, we review different authentication schemes and propose an architecture that enables DCs to authenticate DSs with the help of independent Identity Providers in a secure and privacy-preserving manner by utilizing attribute-based credentials and eIDs. Our work contributes to a more standardized and privacy-preserving way of authenticating DSs, which will benefit both DCs and DSs.</abstract><pub>Springer Nature</pub><oa>free_for_read</oa></addata></record>
fulltext fulltext
identifier ISBN: 9783031579783
ispartof
issn
language nor
recordid cdi_cristin_nora_10852_110699
source NORA - Norwegian Open Research Archives; Springer Books
title Secure and Privacy-Preserving Authentication for Data Subject Rights Enforcement
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-02-06T14%3A02%3A07IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-cristin&rft_val_fmt=info:ofi/fmt:kev:mtx:book&rft.genre=book&rft.btitle=Secure%20and%20Privacy-Preserving%20Authentication%20for%20Data%20Subject%20Rights%20Enforcement&rft.au=Hansen,%20Malte&rft.date=2024&rft.isbn=9783031579783&rft.isbn_list=303157978X&rft_id=info:doi/&rft_dat=%3Ccristin%3E10852_110699%3C/cristin%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true