Privacy Preserving Access Control in Service-Oriented Architecture

被引:5
|
作者
Ranchal, Rohit [1 ]
Bhargava, Bharat [2 ]
Fernando, Ruchith [2 ]
Lei, Hui [1 ]
Jin, Zhongjun [3 ]
机构
[1] IBM Corp, Watson Hlth Cloud, Cambridge, MA 02142 USA
[2] Purdue Univ, Comp Sci, W Lafayette, IN USA
[3] Univ Michigan, Comp Sci & Engn, Ann Arbor, MI USA
关键词
service-oriented architecture; composite services; policy enforcement; active bundle; privacy; access control; WEB SERVICES;
D O I
10.1109/ICWS.2016.60
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Service-oriented Architecture (SOA) comprises a number of loosely-coupled independent services, which collaborate, interact and share data to accomplish incoming requests. A service invocation can involve multiple services, where each service accesses, processes and shares the client's data. These interactions may share data with unauthorized services and violate client's privacy. The client has no means of identifying if a violation occurred because it has no control over the service invocations beyond its trust domain. Such interactions introduce new security challenges which are not present in traditional systems. This paper proposes a data-centric approach for privacy preserving access control in SOA. Benefits of the proposed approach include the ability to dynamically define access polices by the clients and control data access at the time of each service interaction. A realistic healthcare scenario is used to evaluate the implementation of the proposed solution which validates its viability.
引用
收藏
页码:412 / 419
页数:8
相关论文
共 50 条
  • [1] A situation-aware access control based privacy-preserving service matchmaking approach for Service-Oriented Architecture
    Yau, Stephen S.
    Liu, Junwei
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 1056 - +
  • [2] Service-Oriented Architecture for Privacy-Preserving Data Mashup
    Trojer, Thomas
    Fung, Benjamin C. M.
    Hung, Patrick C. K.
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, VOLS 1 AND 2, 2009, : 767 - +
  • [3] Exploration of access control mechanisms for service-oriented network architecture
    Rudra, Bhawana
    Vyas, O. P.
    [J]. INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2015, 9 (01) : 1 - 11
  • [4] Intelligent security and access control framework for service-oriented architecture
    El Yamany, Hany F.
    Capretz, Miriam A. M.
    Allison, David S.
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2010, 52 (02) : 220 - 236
  • [5] Ontology Management in a Service-oriented Architecture Architecture of a Knowledge Base Access Service
    Mossgraber, Juergen
    Rospocher, Marco
    [J]. 2012 23RD INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS (DEXA), 2012, : 289 - 293
  • [6] A Service-Oriented Hybrid Access Network and Clouds Architecture
    Velasco, Luis
    Contreras, Luis Miguel
    Ferraris, Giuseppe
    Stavdas, Alexandros
    Cugini, Filippo
    Wiegand, Manfred
    Fernandez-Palacios, Juan Pedro
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 159 - 165
  • [7] Towards Protecting Consumer's Privacy in Service-Oriented Architecture
    Garcia, Diego
    Toledo, M. Beatriz F.
    Capretz, Miriam A. M.
    Allison, David S.
    Grace, Paul
    Blair, Gordon S.
    [J]. IEEE TIC-STH 09: 2009 IEEE TORONTO INTERNATIONAL CONFERENCE: SCIENCE AND TECHNOLOGY FOR HUMANITY, 2009, : 473 - 478
  • [8] A Fine-Grained Privacy Structure for Service-Oriented Architecture
    Allison, David S.
    El Yamany, Hany F.
    Capretz, Miriam A. M.
    [J]. 2009 IEEE 33RD INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOLS 1 AND 2, 2009, : 628 - 629
  • [9] Service-oriented architecture
    Perrey, R
    Lycett, M
    [J]. 2003 SYMPOSIUM ON APPLICATIONS AND THE INTERNET WORKSHOPS, PROCEEDINGS, 2003, : 116 - 119
  • [10] A service-oriented data access control model
    Meng, Wei
    Li, Fengmin
    Pan, Juchen
    Song, Song
    Bian, Jiali
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON ELECTRONICS AND INFORMATION ENGINEERING, 2017, 10322