JustAct: Actions Universally Justified by Partial Dynamic Policies
摘要
Inter-organisational data exchange is regulated by norms originating from sources ranging from individual consent to (inter)national laws. Verifying norm-compliance is complex because laws (e.g., GDPR) distribute responsibility and require accountability. Moreover, in some domains (e.g., healthcare), the norms themselves may be private. In contrast, standard solutions (e.g., access- and usage-control, smart contracts) reason about policies that are assumed to be public. Instead, we present a novel framework prescribing how decentralised agents decide which actions are justified, despite their partial views of the policy. Crucially, justifications are universal, e.g., accepted by future auditors. Agents establish a common notion of compliance through an (externally synchronized) agreement, which is the basis of each justification defined by policy fragments agents autonomously create, gossip, and assemble. We demonstrate our framework with a federated medical data processing system, using Datalog with weak negation as a minimal policy language.