Privacy Preserving Access Control in Service-Oriented Architecture

被引:5
|
作者
Ranchal, Rohit [1 ]
Bhargava, Bharat [2 ]
Fernando, Ruchith [2 ]
Lei, Hui [1 ]
Jin, Zhongjun [3 ]
机构
[1] IBM Corp, Watson Hlth Cloud, Cambridge, MA 02142 USA
[2] Purdue Univ, Comp Sci, W Lafayette, IN USA
[3] Univ Michigan, Comp Sci & Engn, Ann Arbor, MI USA
关键词
service-oriented architecture; composite services; policy enforcement; active bundle; privacy; access control; WEB SERVICES;
D O I
10.1109/ICWS.2016.60
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Service-oriented Architecture (SOA) comprises a number of loosely-coupled independent services, which collaborate, interact and share data to accomplish incoming requests. A service invocation can involve multiple services, where each service accesses, processes and shares the client's data. These interactions may share data with unauthorized services and violate client's privacy. The client has no means of identifying if a violation occurred because it has no control over the service invocations beyond its trust domain. Such interactions introduce new security challenges which are not present in traditional systems. This paper proposes a data-centric approach for privacy preserving access control in SOA. Benefits of the proposed approach include the ability to dynamically define access polices by the clients and control data access at the time of each service interaction. A realistic healthcare scenario is used to evaluate the implementation of the proposed solution which validates its viability.
引用
下载
收藏
页码:412 / 419
页数:8
相关论文
共 50 条
  • [21] Service-oriented architecture of TeleCARE
    Guevara-Masis, V
    Afsarmanesh, H
    Hertzberger, LO
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2004: OTM 2004 WORKSHOPS, PROCEEDINGS, 2004, 3292 : 14 - 16
  • [22] A view on service-oriented architecture
    Chung, Jen-Yao
    Chao, Kuo-Ming
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2007, 1 (02) : 93 - 95
  • [23] Decentralising a service-oriented architecture
    Sacha, Jan
    Biskupski, Bartosz
    Dahlem, Dominik
    Cunningham, Raymond
    Meier, Rene
    Dowling, Jim
    Haahr, Mads
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2010, 3 (04) : 323 - 350
  • [24] Decentralising a service-oriented architecture
    Jan Sacha
    Bartosz Biskupski
    Dominik Dahlem
    Raymond Cunningham
    René Meier
    Jim Dowling
    Mads Haahr
    Peer-to-Peer Networking and Applications, 2010, 3 : 323 - 350
  • [25] Service-oriented architecture and computing
    Purao, Sandeep
    Khatri, Vijay
    Cameron, Brian
    Journal of Database Management, 2011, 22 (02)
  • [26] Service-Oriented Architecture Roadmapping
    Shan, Tony C.
    Hua, Winnie W.
    2009 IEEE CONGRESS ON SERVICES (SERVICES-1 2009), VOLS 1 AND 2, 2009, : 475 - +
  • [27] Architecture of service-oriented applications
    M. S. Ivanov
    Automatic Documentation and Mathematical Linguistics, 2007, 41 (6) : 251 - 254
  • [28] An Adaptive Service-Oriented Architecture
    Hiel, Marcel
    Weigand, Hans
    Van Den Heuvel, Willem-Jan
    ENTERPRISE INTEROPERABILITY III: NEW CHALLENGES AND INDUSTRIAL APPROACHES, 2008, : 197 - 208
  • [29] Architecture of Service-Oriented Applications
    Ivanov, M. S.
    AUTOMATIC DOCUMENTATION AND MATHEMATICAL LINGUISTICS, 2007, 41 (06) : 251 - 254
  • [30] Service-Oriented Architecture Maturity
    Welke, Richard
    Hirschheim, Rudy
    Schwarz, Andrew
    COMPUTER, 2011, 44 (02) : 61 - 67