Privacy Enhancing Identity Management Using the Semantic Web


To investigate whether the W3C’s semantic web suite of standards may be used to improve privacy protection in identity management scenarios.


PhD Thesis:

The research project has been summarized as part of a PhD thesis defended at the Gdansk University of Technology in 2010:

Giles Hogben:
"A privacy enhancing identity management framework using the semantic web"
(The Polish title: " Wspomagająca prywatność struktura ramowa zarządzania tożsamością z wykorzystaniem Semantic Web”)
Download PDF (2.7 MB)


The domain of this report is the protection of privacy in the request and disclosure of personally identifiable data: privacy enhancing electronic identity management. The report identifies a set of requirements in this domain, which are not satisfied by existing identity management frameworks. This includes important requirements imposed by European data protection legislation as well as those for integrating privacy protection frameworks into enterprise data architectures and common data exchange scenarios.

The report shows how a new model of identity, along with a proposed Semantic Web Identity Management (SWIM) Framework, can be used to satisfy these requirements.


The report achieves this through the following steps:

  • The definition of a set of scenarios as a basis for deriving requirements for privacy and identity management frameworks.

  • A review of existing technologies and frameworks related to the proposition. There is a particular focus on W3C’s P3P 1.0 and P3P 1.1 specifications since these are the most important existing standards in the problem space.

  • A review of the legal and regulatory environment in which these scenarios take place. This is an important source of requirements for the framework.

  • A formal model of important concepts used in Identity Management and their relationships.

  • On the basis of the above scenarios, the above identity model the derivation of a set of legal and technical requirements for a privacy and identity management framework.

  • A gap analysis with existing available technologies applicable to these scenarios.

  • A proposal for semantics, syntax, architecture and technologies for prototype implementation, which satisfy the requirements, that is, the SWIM framework.

  • An experimental validation of the SWIM framework via a prototype implementation and a set of key test cases focusing on the satisfaction of the requirements.

  • Review of the SWIM framework and benchmarking against the requirements.


  • The thesis project was officially begun in 2006.

  • The main research was conducted as part of the EU’s PRIME (Privacy and Identity Management in Europe) project between 2004 and 2006.

  • Between 2006 and 2009, the work done as part of the PRIME project was refined and enhanced into a holistic framework, called the SWIM (Semantic Web Identity Management) framework, described in the report.

  • The thesis was defended in March 2010.


The most innovative contribution of this thesis is a framework which provides:

  • A formal, consistent and comprehensive model of identity concepts with many important implications.

  • The ability to manage private credentials as evidence for identity data.

  • The expressivity to allow truly minimised requests for data.

  • Policy evaluation over inferences from data.

  • Consistent and user-friendly display of human-readable information.

  • The ability to define rules governing for credential release based on usage history and linkability implications.


