<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Semantic Knowledge and Privacy in the Physical Web</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Prajit Kumar Das</string-name>
          <email>prajit1@umbc.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Abhay Kashyap</string-name>
          <email>abhay1@umbc.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Gurpreet Singh</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Cynthia Matuszek</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tim Finin</string-name>
          <email>finin@umbc.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Anupam Joshi</string-name>
          <email>joshi@umbc.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Maryland</institution>
          ,
          <addr-line>Baltimore County, Baltimore, Maryland</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In the past few years, the Internet of Things has started to become a reality; however, its growth has been hampered by privacy and security concerns. One promising approach is to use Semantic Web technologies to mitigate privacy concerns in an informed, exible way. We present Carlton, a framework for managing data privacy for entities in a Physical Web deployment using Semantic Web technologies. Carlton uses context-sensitive privacy policies to protect privacy of organizational and personnel data. We provide use case scenarios where natural language queries for data are handled by the system, and show how privacy policies may be used to manage data privacy in such scenarios, based on an ontology of concepts that can be used as rule antecedents in customizable privacy policies.</p>
      </abstract>
      <kwd-group>
        <kwd>physical web</kwd>
        <kwd>internet of things</kwd>
        <kwd>privacy</kwd>
        <kwd>context sensitive policies</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>In the past few years, the Internet of Things (IoT) has started to become a
reality. Advances like a ordable Bluetooth Low Energy devices, the Physical
Web protocol, and ubiquitous devices such as smart-phones and smart-watches
make it possible for people to communicate with devices and places in the world
around them usefully and intuitively. Unfortunately, the lack of good privacy
and security solutions for ubiquitous sensors and interconnected devices is a
continuing concern. Existing approaches to managing privacy tend to assume
a closed system, in which known users with known needs can be matched to
prede ned policies; the open, mobile nature of the IoT requires more semantically
informed solutions. It is a system where devices need to advertise and discover
others in their vicinity, interoperate with them in a given context, and publish
and honor their privacy and security constraints.</p>
      <p>
        The UN specialized agency responsible for issues concerning information and
communication technologies have de ned the Internet of Things as a global
infrastructure for the information society, enabling advanced services by
interconnecting (physical and virtual) things based on existing and evolving
interoperable information and communication technologies [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. The Physical Web, a
concept rst introduced by Google, is a concretization of IoT. As per Google's
de nition, \The Physical Web is an open approach to enable quick and seamless
interactions with physical objects and locations." The Physical Web works by
broadcasting small packets of data or URLs using the Bluetooth Low Energy
(BLE) protocol and beacons.
      </p>
      <p>
        Over the past few years, we have observed a rise in usage of IoT devices in
various domains. However, the IoT domain has also been criticized for privacy
and security issues that plague these devices. One major cause for concern stems
from a lack of interoperability among manufacturers and the devices they
create. Most IoT systems today are built in a bottom-up manner|that is, deployed
sensors talk to custom and proprietary gateways, which in turn expose
proprietary services; at the highest level manufacturers provide intelligent applications
based on data from those services. This vertical architecture, which is controlled
by manufacturers, hampers horizontal interoperability [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] across manufacturers.
Meanwhile, a typical IoT deployment consists of a heterogeneous collection of
devices. As a result, it becomes di cult to create data privacy and security
solutions.
      </p>
      <p>
        Semantic Web technology uses the general Web architecture, e.g., URIs to
access data, with such access potentially controlled based on rules de ned in
a knowledge base (KB). Semantic Web has been used to de ne access control
rules in various domains, e.g., mobile applications, smart meeting rooms, RDF
triple stores, Social Media, etc. [
        <xref ref-type="bibr" rid="ref11 ref2 ref22 ref27 ref3 ref4 ref8">22,2,8,11,4,27,3</xref>
        ] In this paper, we present the
Carlton framework, which allows us to manage data privacy for entities in
a Physical Web deployment using Semantic Web technologies. We also present
part of the Carlton ontology (see Figure 2), which allows policies to be de ned
based on entity relationships.
      </p>
      <p>Our proof-of-concept study involves a deployment at our organization, where
we study a set of use cases pertaining to queries about persons, places and
events associated with the organization. Our goal is to protect the privacy of
organizational and personnel data. We examine cases where a user's data privacy
is managed by their personal privacy policies. We also study scenarios which
handle data privacy in the absence of a personal privacy policy, or in case of
queries about places and events. Privacy policies in our framework are
contextsensitive; as such, they are dependent on user context, where a user is either
(1): a person whose data is represented in the system; or (2): a person who is
querying the system. In the following sections we will describe the Carlton
system and some initial scenarios, followed by a discussion of ways in which a
similar architecture could support more sophisticated privacy reasoning.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Related Work</title>
      <p>
        Role Based Access Control (RBAC) [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] and Attribute Based Access Control
(ABAC) [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] are two most popular access control models, that have been used
to achieve the goal of managing access control, in various domains. In the mobile
domain, Ghosh et. al. [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] used a semantically rich context model to manage
data ow among applications and lter them at a deeper granularity than it
was possible using available security mechanisms on smart-phones. The CRe^PE
system [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] was one of the earliest known ABAC model implementations using
the XACML standard [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] for ne-grained context-related policy enforcement
on smart-phones. CRe^PE didn't use Semantic Web but it followed the ABAC
model. Carlton applies techniques learned in mobile domain to IoT domain and
uses context-sensitive policies to de ne access to organizational and personnel
data. Our access control model is an ABAC model where the attributes de ning
data access are `requesting user' context, `requested entity' context and a query.
      </p>
      <p>
        Using policy based security is not a new technique. Kagal et. al. [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] used
distributed policy management as an alternative to traditional authentication
and access control schemes. Rei, a policy language described in OWL and
modeled on deontic concepts of permissions, prohibitions, obligations and
dispensations [
        <xref ref-type="bibr" rid="ref20 ref22">20,22</xref>
        ], have used Semantic Web technologies to express what an entity
can/cannot do and what it should/should not do. In Rei, credentials and
entity properties like user, agent, etc are associated with access privileges. This
allowed Rei to describe a large variety of policies ranging from security policies
to conversation and behavior policies. The Rein framework [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] which builds on
Rei and is based on N3 rules and uses a CWM reasoning engine for distributed
reasoning. In Carlton we de ne data sharing policies that determines behavior
of the Physical Web-Mobile Agent interaction.
      </p>
      <p>
        KAoS [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ] relies on a DAML description-logic-based ontology of the
computational environment, application context, and the policies. The KAoS system
was capable of supporting runtime policy changes and was extensible to a variety
of platforms. In ROWLBAC [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], the Web Ontology Language (OWL) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] was
used to support the standard RBAC model and extending OWL constructs used
to model ABAC. All of these systems are using some Semantic Web technology
for their implementation. In our work, we use Semantic Web technology through
an ontology to de ne a hierarchical context model for a user and a requester
an rules are de ned using the Semantic Web Rule Language [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] to determine
access control decisions. In short, we are achieving the goal of access control
in a di erent domain with techniques that have been proven to work in other
domains. We do modify the system design, if and when required, to suite our
needs for the IoT domain and particular use cases we handle,
      </p>
      <p>
        The hierarchical notion of context de ned in this paper is an extension of
our previous work [
        <xref ref-type="bibr" rid="ref19 ref29">19,29</xref>
        ] where the part of relationship was de ned for stating
that a location is subsumed by another bigger location. We have extended this
notion to Identity context as explained in Subsection 3.2.
      </p>
      <p>
        A model for context-sensitive policy based access control for IoT was
presented in our previous work [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], where we proposed a system design that achieves
such a goal for a generic IoT environment. We capture access control policies
using the ABAC model represented in OWL. We used a vehicular IoT use case
for describing our policies in that work. Carlton in contrast doesn't yet have a
well-de ned mechanism for capturing policy modi cation, as de ned in the other
system. However, Carlton handles far more complex use cases with respect to
the contextual granularity of queries made to the system.
      </p>
      <p>
        Finally, we take a look at indirect vs obvious privacy implications. Ma et.
al. [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] showed in their study how a relatively small amount of `side' information
can lead to signi cant privacy concerns. We try to address such issues with the
current best available solution of writing a few general rules to make our system
usable. A detailed discussion on this can be found in the Section 4.1.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>System Overview</title>
      <p>The prototype Carlton application targeted in this work is a pervasive
information system that uses beacons (low powered, battery e cient devices that
broadcast content over Bluetooth), xed-position kiosks, mobile devices, and a
NLP engine to respond to natural language queries. Beacons are deployed in key
locations in the department, like o ces, classrooms, and labs. The application
is intended to provide `Help Desk'-style information about an academic
department, allowing people to ask questions and get spoken responses, sometimes
augmented with an appropriate display.</p>
      <p>
        One of our goals is to design a system that could be installed by other
university departments and customized by providing a database of key information
about its people and places. Both kiosks and mobile devices use beacons to know
their locations, using the Nearby Messages API [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. This maximizes portability
and enables use of user location context when interpreting and responding to
questions, which allows responses to be physically informed. Table 1 shows a
few examples of supported question types, including possible privacy concerns;
Section 5 gives more examples of the kinds of questions Carlton is intended
to address. Further details about context are inferred using an ontology and
external sources of data like a user's calendar if it is shared with the system.
      </p>
      <p>
        The Carlton system architecture is shown in Figure 1. The system is
invoked by a user by asking queries as either natural language text or speech
through our kiosk or our Carlton Android app. Spoken language is converted
to text using a SpeechRecognizer service in the Android app, that is part of
Android SDK[
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] or using the Cloud Speech API [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] in the kiosk. Text, whether
from the speech to text system or entered directly, is then processed using the
Stanford CoreNLP suite of tools [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] to do POS tagging, parsing and identify
entities and relations. A simple system takes this output and attempts to map
it into one of the requests, questions or assertions that our system can handle.
The responses from our system are always in text form but if the query was
made using speech through the Carlton Android app, we use Android SDK's
TextToSpeech service [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] to speak the response back to the user.
      </p>
      <p>Context is retrieved from an ontology as well as from external sources such
as location. Users have the option of identifying themselves; users who lack
credentials, or who do not identify themselves, will potentially receive more
limited data, depending on privacy policies. A reasoning engine uses inferred
context, the user's speech act and de ned privacy policy as input, to reason
Additional
Context
User identity;
room
calendar
Conference ITE
conroom ference
room</p>
      <p>Main
deDr. A Joshi partment User identity;
o ce target
disam</p>
      <p>biguation;</p>
      <p>Hall out- target
Dr. K Joshi side faculty location
o ce</p>
      <p>Response
\No; shall I book it
for 2PM-3PM?"
\No. See the front
desk for room
reservations."
\The chairman is
not in the o ce
right now."
\No. Would you like
to hear her o ce
hours?"
User</p>
      <p>Query</p>
      <p>Target</p>
      <p>Location</p>
      <p>Faculty
1
member
\Is this
room
booked
2 Student from
2PM</p>
      <p>3PM?"</p>
      <p>Sta
3
member
\Is Dr.</p>
      <p>Joshi
4 iSntucdlaesnst here?"
5
6</p>
      <p>Visitor \Where is</p>
      <p>Dr. Tim
Finin's
o ce?"
7 Student</p>
      <p>ITE build- Building o ce \Please see the
ing third map; target front desk in ITE</p>
      <p>oor disambiguation 325 for directions."
Dr. T Finin</p>
      <p>Admin
building</p>
      <p>Target
biguation</p>
      <p>
        \Please see the
pubdisam- licly available
campus directory or the
information desk."
User identity;
campus direc- \His o ce is in the
tory; target ITE building."
disambiguation
over, and infer the granularity at which data or descriptions will be shared in
the response. After the response is generated, a natural language query response
is generated and presented, either as text or speech. Table 1 shows some examples
of queries, context, and responses.
Carlton uses context-sensitive privacy policy rules de ned in the Semantic Web
Rule Language (SWRL) [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] to manage the privacy of data. The abstract syntax
for SWRL rules follow the Extended Backus-Naur Form (EBNF) notation which,
while useful for XML and RDF serializations, isn't particularly easy to read. For
readability, we use the following informal format: antecedent ) consequent.
Antecedent(s) must hold for a consequent to apply. Multiple antecedents in a
rule are de ned as a conjunctions of atoms. The consequent atom states whether
the access is allowed or denied.
      </p>
      <p>Antecedents in our rule speci cation consist of the context of a requesting
entity, along with the entity type that is being requested, and may also include
context for the entity whose data is requested.</p>
      <p>A more abstract representation may be considered as a triple (U, C, Q)
which contains: U, that represents requested user's context, that is the user
whose data is represented in the system. C is requesting user's context, that
is the user who is querying the system. Q is the query that is received by the
system. The following is an example policy rule with instantiated values, based on
our ontology, which demonstrates how information is controlled by our system.
Imagine a scenario where Professor Xavier shares information about his present
precise location with a person, if they are member of his lab and he supervises
them, given he is not speaking at a talk at the moment. The rst 8 predicates in
this policy rule represent the requester student's context. The next 8 relate to
the requested party's context. The query is about location request and response
from the system is to share the location.</p>
      <p>Example 1.
@prefix crltn :&lt; https :// www . ebiquity . org / ontologies / carlton
/0.1 &gt;.
@prefix swrlb :&lt; http :// www .w3. org /2003/11/ swrlb &gt;.
crltn : student (? requester ) ^
( crltn : supervises (\Xavier00 ,? requester ) _
( crltn : affiliatedWith (? requester ,? labName ) ^
crltn : leads (\Xavier00 ,? labName )) ) ^
crltn : hasCurrentLocation (? requester ,? aBldgLocation ) ^
crltn : room (? aBldgLocation ) ^
crltn : sitsIn (\Xavier00, aBldgLocation ) ^
crltn : currentTime (? currTime ) ^
swrlb : Exists (? anEvent ) ^
crltn : speakingAt (\Xavier00 ,? anEvent ) ^
( ( crltn : startTime (? anEvent ,? eventStartTime ) ^
swrlb : greaterThan (? eventStartTime ,? currTime )) _
( crltn : endTime (? anEvent ,? eventEndTime ) ^
swrlb : greaterThan (? currTime ,? eventEndTime )) ) ^
crltn : hasCurrentLocation (\Xavier00 ,? aLocation ) ^
crltn : Location (? aLocation ) ^
crltn : requestLocation (\Xavier00)
=)
shareLocation (? aLocation )
On the other hand, if a student is simply a liated with the same department as
he is, Professor Xavier might share a generic location using the privacy policy
rule shown below.</p>
      <p>Example 2.
@prefix crltn :&lt; https :// www . ebiquity . org / ontologies / carlton
/0.1 &gt;.
@prefix swrlb :&lt; http :// www .w3. org /2003/11/ swrlb &gt;.
crltn : student (? requester ) ^
crltn : affiliatedWith (? requester ,? deptName ) ^
crltn : affiliatedWith (\Xavier00 ,? deptName ) ^
crltn : hasCurrentLocation (\Xavier00 ,? aLocation ) ^
crltn : Location (? aLocation ) ^
crltn : partOf (? aLocation ,? city ) ^
crltn : City (? city ) ^
crltn : requestLocation (\Xavier00)
=)
shareLocation (? city )
3.2</p>
      <p>
        User Context Speci cation
Context has been de ned by Dey and Abowd [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] as:
\[...] any information that can be used to characterize the situation of an
entity (i.e., identity, location, activity, time). An entity is a person, place,
object or events that is considered relevant to the interaction between a
user and application, including the user and applications themselves."
In our system, user context is considered from a perspective of both who is
querying the system and who the query is about. Both of these user contexts
include location, identity and activity information. For the use cases discussed
in this paper we have not considered temporal context. We use the Physical
Web to sense user location using beacons. This information is then sent to a
back-end knowledge base that uses a context ontology and an inference engine
to determine user location context. The identity context is de ned by voluntary
user sign-in and authentication. The activity context is linked to the identity of
a user in our system, as activity context is derived from the user's calendar data.
This provides both static and dynamic context to evaluate against data privacy
rules.
      </p>
      <p>
        An interesting feature of our system is that we wish to protect the privacy of
the user querying the system, as well as the information being queried. Identi
cation does have privacy repercussions, and therefore we have designed our system
to be capable of working without identifying a user. When context information
is not available, or if only generic context information is available (e.g., `the user
is a student'), we evaluate data privacy rules accordingly by using rules with
more generic contextual antecedents. We are able to do this using our ontology,
which allows location and activity generalization by using partOf relationships
among location entities and activity hierarchies. The generalization technique
described here is an extension of our work in data privacy in the mobile
domain [
        <xref ref-type="bibr" rid="ref11 ref19 ref29">19,29,11</xref>
        ]. We use the owl:sameAs property to incorporate certain classes
and properties from the Platys [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] and Place [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ] ontologies. These ontologies
have been previously used for de ning user location and activity context in a
hierarchical manner.
      </p>
      <p>This technique helps us preserve privacy by sharing data with varying levels
of granularity, as speci ed by policies. It involves replacing a value with a less
speci c but semantically consistent value. As an example of location
generalization, a user might de ne a policy stating that \My building level location can be
shared with my colleagues," which allows partial location sharing with anyone
who is identi ed as a `colleague', based on rules written in our system. In this
case, if an exact room location of a user is known, the ontology allows us to
generalize to a building using the \Part Of" transitive property. In our
ontology Location is a super class of the Room, Building, City, State and Country
classes. The various sub-classes are used to denote di erent levels of abstractions
for the location.</p>
      <p>Activity generalization is similar. Consider a case where we have a hierarchy
of work activities:
working
partOf
meeting
partOf
department meeting</p>
      <p>lab meeting
partOf</p>
      <p>This hierarchy lets a user de ne policies like \Share with team members
when I am in a team meeting" and \Share with team non-members when I am
in a meeting." This is especially useful if we consider that a team meeting might
be accessible only to team members, as it allows obfuscating the data to just
a \meeting" when the party querying the data is allowed some access but not
access to con dential team data.</p>
      <p>We look at identity based generalization in this paper as an extension of the
generalization technique. Our ontology contains a Person class with a property
affiliatedWith that de nes if a requester is \a liated with" a university,
department or research group. If the user is not a liated with any instances of
these classes that match the a liation of an entity whose data was requested,
we generalize the response accordingly. This allows us to de ne rules like \Share
with non-members of the organization only my city level location info".
3.3</p>
      <p>Semantic Knowledge
The Carlton ontology de nes entity relationships between persons, locations
and events in the organizational structure. We are able to make inferences of the
form described in Section 5 based on the entity relationship properties de ned in
the ontology. See Figure 2 for details of the ontology. The four primary classes
de ned in our ontology include Person, Location, Organization and Event.
A Person in our ontology might be a Faculty, Staff, Student or Visitor to
the organization. Organization is further broken into University, Department,
ResearchGroup classes. Event have the sub-classes Talk, Meeting and Course.
For the Location class partOf relationship allows hierarchical location context
de nition. The same applies to the Organization sub-classes. The Person class
allows us to infer a liation with an Organization. A Visitor is a Person in
our ontology and might have a a liation too, with an Organization but the
instance of a visitor's Organization would not match Organization information
for Faculty, Staff or Student from a particular University that the Visitor
does not belong to. We are able to infer Location of an Event through the
relationship heldAt between Event and Room classes. Obviously a Talk will be
held in a ConferenceRoom, a Course will be taught in a Classroom etc. where the
rooms are types of the Room class and therefore using the heldAt relationship we
are able to infer triples that state such a relationship. Similar inference maybe
drawn for a liation of a Faculty, Staff or Student with a Department or
ResearchGroup.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Privacy Implications</title>
      <p>The system described in this paper takes steps towards ful lling the promise
of the Internet of Things: it allows easy access to appropriately contextualized
knowledge, making it possible for users to nd appropriate information quickly
and easily while reducing administrative overhead. Consistent with that,
however, it also showcases some of the privacy concerns associated with precisely
those capabilities. In this section, we look at some of the ways in which privacy
comes into play in such a system, and discuss how using a semantically informed
knowledge framework allows for informed, appropriate behavior.
4.1</p>
      <p>Privacy Stakeholders
One consideration when discussing privacy concerns is the correct identi cation
of stakeholders, individuals or groups whose privacy may be compromised. Some
stakeholders are easily identi ed, while others may be more subtle. The same
is true of the possible impact of di erent kinds of information access, that is,
privacy failures may range from obvious to indirect. We consider three possible
stakeholders and, for each, discuss selected privacy concerns.</p>
      <p>The most obvious stakeholder group is query targets: individuals about whom
queries are posed. Information about query targets may be very direct, as in
location, or more general, such as working at a particular research lab. In addition,
this information varies in consistency across time: location presumably changes
frequently, whereas membership in the Faculty group is usually permanent.
Broadly speaking, query targets can be assumed to have some (but not
complete) control over their own information; as an example, the department may
make information available about professors' o ce hours, but not otherwise
provide information from calendars, while an individual may choose to make their
meeting times available to their own students.</p>
      <p>Less obviously, target privacy may also apply to entire organizations or
subgroups. While an academic department may be relatively public, some types of
information may still be protected. As an example, what research groups
exist within the department is likely to be public information, but the physical
location of labs engaged in controversial research may not be. Similarly, a
research group may or may not choose to make their group meeting time public,
depending on member preference and research topic.</p>
      <p>
        The nal stakeholder whose privacy must be considered is the Carlton
user. The pattern of a user's queries may reveal unwarranted information|
for example, a professor might look askance on a student continually asking
about lab meeting times, even if the student is punctual; if a faculty member
consistently asks about the chair's location and then manages to \just miss" him
or her, active avoidance might be deduced. Even a user who does not identify
him or herself may be de-anonymizable after relatively few queries. [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] In most
cases, this may be addressed as treating queries as strictly transient unless the
user engages in an action that makes changes to the world (e.g., reserving a
conference room); however, this disallows logging of the sort that is commonly
used for debugging and system optimization.
4.2
      </p>
      <p>Semantically Informed Access and Risks
Having a formal, semantic representation of the underpinnings of information to
be accessed and actions to be taken allows for the formal representation of
policies as rules. Carlton combines information about users, contexts, and query
targets as antecedents to rules that allow users to express complex sets of
constraints on information that can be shared. Information can be controlled based
on the user or the query target (as shown in Example 2), the user's location (as
shown in Table 1), or more generally|for example, the department might write
default rules that prohibit the sharing of information about peoples' locations.
Such a rule should include an antecedent specifying that it applies only if there
is no more permissive target-speci c rule.</p>
      <p>Semantic hierarchies also make it possible to provide \fall-upward"
information. Example 1 shows a case in which only the City of the query target is
explicitly provided, rather than the speci c location. However, because rules can
be expressed with arbitrary complexity, such rules can be speci ed implicitly in
both antecedent and consequent. A generalized policy might, for example, say
\For members of the academic community, give a summary of my daily schedule;
otherwise, provide no information." Such a policy would chain with more general
rules about a liation and summarization; this is explored further in Section 5
below.</p>
      <p>One notable category of privacy failures in a rule-based system is
combinatorial failures, that is, failures in which multiple pieces of allowed information
lead to a conclusion that is not intended to be public. This is a concern for
overlapping rules with varying privacy implications. As an example, Professor Grey
does not allow anyone to see her location or calendar. Dr. Xavier does not allow
anyone to see his location, but allows his students to see his calendar, meaning
that they can nd out that he is in a meeting with Dr. Grey and Dr. Hank
McCoy. Dr. McCoy does not allow access to his calendar, but makes his location
available to anyone. With a small number of queries, Dr. Xavier's students can
nd the location and current calendar event of all three professors.</p>
      <p>This is a di cult problem to address. Determining whether any combination
of rules will allow for unintended access would be excessively restrictive. More
importantly, it is isomorphic to a complete truth maintenance problem, and not
tractable for a knowledge base of reasonable size. While it is possible to write
additional rules that explicitly restrict information access in addition to explicitly
exposing it, this solution is not logically complete and is, additionally, prone to
logical con icts unless rules occur in a strict precedence ordering. The current
best available solution is to write relatively few, fairly general rules, and consider
the output in di erent cases carefully; while unsatisfying, this is currently the
best case for achieving a usable system.
5</p>
    </sec>
    <sec id="sec-5">
      <title>Use Case Scenarios</title>
      <p>We are developing and testing the Carlton prototype in an academic Computer
Science department. A number of beacons have been deployed in our University's
Information Technology and Engineering (ITE) building's front o ce suite,
ofces of faculty members, labs and conference rooms. Carlton is capable of
handling a variety of natural language queries, e.g., \Who is Foggy Nelson?",
\Where is Ben Ulrich's o ce?", \What does Matt Murdock teach?", etc. Since
we have installed our system in an academic organization, we look at use cases
that make sense in such a setting. We will look at use cases in which personal
data privacy policies have been set up by Professor Jean Grey.</p>
      <p>Use Case 1: Share speci c information with people who are nearby and
have a relationship with the query target. Prof. Grey prefers certain private
information to be shared with people she knows who are near her o ce. She
shares her private calendar data with students from a course she is teaching and
with people she advises. This may be de ned using the rule: \Share my calendar
information with people I teach or supervise if they are near my o ce." Such a
query would have relevance in case a student is standing in front of her o ce
and wants to know when she will be available for a meeting.</p>
      <p>Use Case 2: Share only summary information with people who are far away
and have a relationship with the query target. Prof. Grey does not want
her students to skip lab meetings irrespective of whether she is busy in another
meeting or not. Therefore, she sets up a policy stating \Share only summary
information from my calendar with people I supervise if they are far away from
my o ce." According to this policy her students will only get to know that Prof.
Grey is available today and has some meetings unless they are already in the
building.
Use Case 3: Share only publicly available data with unknown people.
Carlton allows Prof. Grey to block anyone who is not part of her group or
school from getting any information from her calendar or any other source that
is private to her group or school. This is a special use case which not only takes
care of data privacy for the professor but it also takes care of privacy implications
from a requester's perspective. We explain this further in Section 6.
Use Case 4: Share information about organization's entities with people who
are nearby and if they belong to the group or organization. Now we look
at privacy of a physical or virtual entity of the organization. The entity in this
scenario maybe a meeting room, a lab or an event. Prof. Grey has a lab called
PhoenixForce. PhoenixForce owns a meeting room denoted as ITE-1, two labs
named ITE-4 and ITE-5, and organizes an event called FallWelcomeBack. Only
researchers from her lab are allowed to book the meeting room, get access to the
lab, or join the event. These require that the requester has information about
when the meeting room is available, whether lab has empty seats, and where the
event is. Carlton is thus able to use privacy policies like \Share meeting room
availability with members of PhoenixForce," \Share lab empty seat count for
ITE-4 if user is near ITE-4 and AND a member of PhoenixForce," and nally
\Share event location with members of PhoenixForce if they are on campus."
Use Case 5: Share public information about an organization's entities with
unknown people. In this use case Carlton unaware of a requester's identity,
and therefore shares only publicly available event information, public lab info
and public meeting room data|for example, that PhoenixForce does Robotics
research and meeting room ITE325 is used for dissertation defenses.
These use cases are intended to showcase how data privacy for an individual or
organization's entities are managed using Physical Web context discovery and
by using privacy policies de ned in Semantic Web technologies.
6</p>
    </sec>
    <sec id="sec-6">
      <title>Trusting the Physical Web</title>
      <p>Although our query client includes a login option, it is not necessary for a user to
log in in order to query our system. One may observe that our use cases include
scenarios where a user's identity is unknown. In these cases we do share less
information but this acts as a feature of our system. If a user logs into our app
then they have authenticated themselves to our system and we may authorize
access to entities as per the privacy policies that have been de ned. However,
this means that the system constantly knows who the user is and where they go
and what they ask etc. This may be considered as a violation of privacy of the
requester.</p>
      <p>In case of the physical web we may be able to determine where a
particular user is at all times, given enough number of beacons are used to ensure
organization-wide coverage. We have thus created a privacy issue for users
requesting data from our system, as a side e ect of actually trying to manage data
privacy for individuals and entities of the organization. How do we address this
issue? We have already alluded to a potential restriction on our system in Use
Cases 3 and 5 that will allow us to reduce some of the privacy concerns. By
not making the login step mandatory, we have reduced these privacy concerns.
Queries are still responded to in this case but we generalize our response based
on the a liation information that we might have.</p>
      <p>
        Is it possible to authenticate a user without knowing the actual identity
of the user? Yes, we have implemented Authentication without Identi cation
using Zero-Knowledge Proof as described by [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. This allows us to respond to
user with a higher level of data granularity. For example all group related data
maybe exposed to a person who has been authenticated to be part of the group.
It's worth noting that we will not be able to respond to queries where identity
context match has to be an exact match. For example if Prof. Grey queries the
system about \When is my meeting with Prof. Xavier scheduled?".
      </p>
      <p>
        The Carlton mobile app does not require any permission other than:
{ android.permission.INTERNET
{ android.permission.ACCESS FINE LOCATION
{ android.permission.BLUETOOTH
These permissions are required to talk to the beacons over the BLE protocol
and to obtain beacon data and call back-end server for query responses over
the internet. The location access is required by the Nearby Messages API [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]
which provides us with all the data associated with a beacon. No identity based
permissions are required by our app. Neither do we take device id information.
The Nearby Messages API doesn't require user authentication for sharing data.
As a result, the system is designed to not share any identity information with
the Google servers, in order to address privacy concerns with regard to explicit
associations being made between user identity and user location by Google.
7
      </p>
    </sec>
    <sec id="sec-7">
      <title>Conclusions and Future Work</title>
      <p>In this paper, we have presented Carlton, a framework for managing data
privacy for entities in a Physical Web deployment using Semantic Web
technologies. Our system used context-sensitive privacy policies to protect privacy
of organizational and personnel data. We have provided few use case
scenarios where natural language queries for data are handled by Carlton. We have
explained how privacy policies may be used to manage data privacy in such
scenarios, based on an ontology of concepts that can be used as rule antecedents in
customizable privacy policies.</p>
      <p>Although we have presented a few use cases in this paper, the number of
scenarios are small relative to fully functional, in-real-life system. The purpose
of use cases that we have presented, was to demonstrate the utility of Carlton.
However, many more scenarios are possible and we intend to explore them all
eventually. A challenge that we constantly faced during this project was
managing the beacons when they are in close proximity. This problem was solved
in a trivial manner by reducing the signal strengths of the beacons. However,
this still doesn't handle con ict resolution in presence of multiple beacons in
close-proximity. Handling, such issues could be a challenging goal to pursue, in
the future.
8</p>
    </sec>
    <sec id="sec-8">
      <title>Acknowledgment</title>
      <p>We gratefully acknowledge the support of the Google Internet of Things (IoT)
Technology Research Award pilot, which provided the hardware used for this
research.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Bechhofer</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          : Owl:
          <article-title>Web ontology language</article-title>
          .
          <source>In: Encyclopedia of Database Systems</source>
          , pp.
          <year>2008</year>
          {
          <year>2009</year>
          . Springer (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kagal</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Perich</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chakraborty</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Intelligent agents meet the semantic web in smart spaces</article-title>
          .
          <source>IEEE Internet Computing</source>
          <volume>8</volume>
          (
          <issue>6</issue>
          ),
          <volume>69</volume>
          {
          <fpage>79</fpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3. Cheng, Y.,
          <string-name>
            <surname>Park</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sandhu</surname>
          </string-name>
          , R.:
          <article-title>A user-to-user relationship-based access control model for online social networks</article-title>
          .
          <source>In: IFIP Annual Conference on Data and Applications Security and Privacy</source>
          . pp.
          <volume>8</volume>
          {
          <fpage>24</fpage>
          . Springer (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Conti</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Crispo</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fernandes</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhauniarovich</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Cr^epe: A system for enforcing ne-grained context-related policies on android</article-title>
          .
          <source>IEEE Transactions on Information Forensics and Security</source>
          <volume>7</volume>
          (
          <issue>5</issue>
          ),
          <volume>1426</volume>
          {
          <fpage>1438</fpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Das</surname>
            ,
            <given-names>P.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Narayanan</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sharma</surname>
            ,
            <given-names>N.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Contextsensitive policy based security in internet of things</article-title>
          .
          <source>In: 2016 IEEE International Conference on Smart Computing (SMARTCOMP)</source>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Desai</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sheth</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anantharam</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Semantic gateway as a service architecture for iot interoperability</article-title>
          .
          <source>In: 2015 IEEE International Conference on Mobile Services</source>
          . pp.
          <volume>313</volume>
          {
          <issue>319</issue>
          (
          <year>June 2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Dey</surname>
            ,
            <given-names>A.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Abowd</surname>
          </string-name>
          , G.D.:
          <article-title>Towards a better understanding of context and contextawareness</article-title>
          .
          <source>In: First Int. symposium on Handheld and Ubiquitous Computing (HUC)</source>
          (
          <year>1999</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Dietzold</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Auer</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Access control on rdf triple stores from a semantic wiki perspective</article-title>
          .
          <source>In: ESWC Workshop on Scripting for the Semantic Web. Citeseer</source>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Ferraiolo</surname>
            ,
            <given-names>D.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kuhn</surname>
            ,
            <given-names>D.R.</given-names>
          </string-name>
          :
          <article-title>Role-based access controls</article-title>
          .
          <source>arXiv preprint arXiv:0903.2171</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kagal</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Niu</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sandhu</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Winsborough</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thuraisingham</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          : Rowlbac:
          <article-title>Representing role based access control in owl</article-title>
          .
          <source>In: Proceedings of the 13th ACM Symposium on Access Control Models and Technologies</source>
          . pp.
          <volume>73</volume>
          {
          <fpage>82</fpage>
          . SACMAT '08,
          <string-name>
            <surname>ACM</surname>
          </string-name>
          , New York, NY, USA (
          <year>2008</year>
          ), http: //doi.acm.
          <source>org/10</source>
          .1145/1377836.1377849
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Ghosh</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jagtap</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Privacy control in smart phones using semantically rich reasoning and context modeling</article-title>
          .
          <source>In: Security and Privacy Workshops (SPW)</source>
          ,
          <source>2012 IEEE Symposium on</source>
          . pp.
          <volume>82</volume>
          {
          <fpage>85</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Godik</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anderson</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Parducci</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Humenn</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vajjhala</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Oasis extensible access control 2 markup language (xacml) 3</article-title>
          . Tech. rep.,
          <source>Tech. rep.</source>
          ,
          <source>OASIS</source>
          (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13. Google: Text to speech (
          <year>September 2009</year>
          ), https://developer.android.com/ reference/android/speech/tts/TextToSpeech.html
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Google</surname>
          </string-name>
          : Speech recognizer (May
          <year>2010</year>
          ), https://developer.android.com/ reference/android/speech/SpeechRecognizer.html
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15. Google:
          <article-title>Cloud speech api</article-title>
          (May
          <year>2016</year>
          ), https://cloud.google.com/speech/
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16. Google:
          <article-title>Google nearby messages api</article-title>
          (May
          <year>2016</year>
          ), https://developers.google. com/nearby/messages/overview
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Horrocks</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Patel-Schneider</surname>
            ,
            <given-names>P.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Boley</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tabet</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grosof</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dean</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>SWRL: A semantic web rule language combining OWL and RuleML. W3c member submission</article-title>
          ,
          <source>World Wide Web Consortium</source>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18. ITU-T: Series y:
          <article-title>Global information infrastructure, internet protocol aspects and next-generation networks</article-title>
          .
          <string-name>
            <surname>ITU-T Recommendation</surname>
            <given-names>Y</given-names>
          </string-name>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Jagtap</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zavala</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Preserving privacy in context-aware systems</article-title>
          .
          <source>In: Semantic Computing (ICSC)</source>
          ,
          <year>2011</year>
          Fifth IEEE International Conference on. pp.
          <volume>149</volume>
          {
          <fpage>153</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Kagal</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>A policy language for a pervasive computing environment</article-title>
          .
          <source>In: Policies for Distributed Systems and Networks</source>
          ,
          <source>2003. Proceedings. POLICY 2003. IEEE 4th International Workshop on</source>
          . pp.
          <volume>63</volume>
          {
          <issue>74</issue>
          (
          <year>June 2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Kagal</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Berners-Lee</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Rein: Where policies meet rules in the semantic web</article-title>
          .
          <source>Computer Science</source>
          and Arti cial . . . (
          <year>2005</year>
          ), http://groups.csail.mit.edu/dig/ 2005/05/rein/rein-paper.pdf
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Kagal</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>A policy based approach to security for the semantic web</article-title>
          .
          <source>In: International Semantic Web Conference</source>
          . pp.
          <volume>402</volume>
          {
          <fpage>418</fpage>
          . Springer (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Kuhn</surname>
            ,
            <given-names>D.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Coyne</surname>
            ,
            <given-names>E.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weil</surname>
            ,
            <given-names>T.R.</given-names>
          </string-name>
          :
          <article-title>Adding attributes to role-based access control</article-title>
          .
          <source>Computer</source>
          <volume>43</volume>
          (
          <issue>6</issue>
          ),
          <volume>79</volume>
          {81 (
          <year>June 2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Lysyanskaya</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Authentication without identi cation</article-title>
          .
          <source>IEEE Security and Privacy</source>
          <volume>5</volume>
          (
          <issue>3</issue>
          ),
          <volume>69</volume>
          {71 (May
          <year>2007</year>
          ), http://dx.doi.org/10.1109/MSP.
          <year>2007</year>
          .52
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Ma</surname>
          </string-name>
          , C.Y.,
          <string-name>
            <surname>Yau</surname>
            ,
            <given-names>D.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yip</surname>
            ,
            <given-names>N.K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rao</surname>
            ,
            <given-names>N.S.:</given-names>
          </string-name>
          <article-title>Privacy vulnerability of published anonymous mobility traces</article-title>
          .
          <source>IEEE/ACM Transactions on Networking</source>
          <volume>21</volume>
          (
          <issue>3</issue>
          ),
          <volume>720</volume>
          {
          <fpage>733</fpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Manning</surname>
            ,
            <given-names>C.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Surdeanu</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bauer</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finkel</surname>
            ,
            <given-names>J.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bethard</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McClosky</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>The stanford corenlp natural language processing toolkit</article-title>
          .
          <source>In: ACL (System Demonstrations)</source>
          . pp.
          <volume>55</volume>
          {
          <issue>60</issue>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Sun</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yong</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wu</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>Semantic access control for cloud computing based on e-healthcare</article-title>
          .
          <source>In: Computer Supported Cooperative Work in Design (CSCWD)</source>
          ,
          <year>2012</year>
          IEEE 16th International Conference on. pp.
          <volume>512</volume>
          {
          <fpage>518</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Uszok</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bradshaw</surname>
            ,
            <given-names>J.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Je</surname>
            <given-names>ers</given-names>
          </string-name>
          , R.:
          <article-title>KAoS: A Policy and Domain Services Framework for Grid Computing and Semantic Web Services</article-title>
          .
          <source>Trust Management {Lecture Notes in Computer Science</source>
          <volume>2995</volume>
          /
          <year>2004</year>
          ,
          <volume>16</volume>
          {
          <fpage>26</fpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Zavala</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dharurkar</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jagtap</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Finin</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Mobile, collaborative, context-aware systems</article-title>
          .
          <source>In: Proc. AAAI Workshop on Activity Context Representation: Techniques and Languages</source>
          , AAAI. AAAI Press (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>