Purpose-Based Privacy Preserving Access Control for Secure Service Provision and Composition

被引:21
|
作者
Amini, Morteza [1 ]
Osanloo, Farnaz [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran 1136511155, Iran
关键词
Cloud computing; software as a service; service composition; access control; privacy preserving; CLOUD; MECHANISM;
D O I
10.1109/TSC.2016.2616875
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two main security issues in software as a service (SaaS) delivery model of cloud environments are access control and privacy preserving in basic web services as well as composite services where we require to infer policies through the automatic composition of the policies specified for their constituting basic services. In this paper, we present a privacy preserving access control model and framework for secure service provision and composition. The model is a combination of an attribute based access control model and a proposed purpose-based privacy model. Following this model, an access request for a service is permitted if the requester's attribute certificates and contextual conditions are in compliance with the access control policies specified by the service provider and simultaneously the privacy preferences of the requester is compatible with the privacy policies of the service provider. In the framework proposed in this paper, for secure service composition, possible chains of composite services are ranked according to the users' preferences and sensitivity level of their data. The security policies of the composite service, established by the chosen chain of services, are inferred by automatic composition of policies specified for the basic services in the chain.
引用
收藏
页码:604 / 620
页数:17
相关论文
共 50 条
  • [1] Dynamic Purpose-based Access Control
    Peng, Huanchun
    Gu, Jun
    Ye, Xiaojun
    PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, 2008, : 695 - 700
  • [2] Enhancing MongoDB with Purpose-Based Access Control
    Colombo, Pietro
    Ferrari, Elena
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2017, 14 (06) : 591 - 604
  • [3] Efficient Privacy-preserving User Identity with Purpose-based Encryption
    Tri Hoang Vo
    Fuhrmann, Woldemar
    Fischer-Hellmann, Klaus-Peter
    Furnell, Steven
    2019 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2019), 2019,
  • [4] A purpose-based access control in native XML databases
    Sun, Lili
    Wang, Hua
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2012, 24 (10): : 1154 - 1166
  • [5] Purpose-Based Access Control Policies and Conflicting Analysis
    Wang, Hua
    Sun, Lili
    Varadharajan, Vijay
    SECURITY AND PRIVACY - SILVER LININGS IN THE CLOUD, 2010, 330 : 217 - +
  • [6] A purpose-based synchronization protocol for secure information flow control
    Enokido, Tomoya
    Takizawa, Makoto
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2010, 25 (02): : 111 - 118
  • [7] Secure and Privacy Preserving RFID Based Access Control to Smart Buildings
    Al-Sudani, Ahmed Raad
    Gao, Shang
    Wen, Sheng
    Al-Khiza'ay, Muhmmad
    SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE (SPACCS 2018), 2018, 11342 : 146 - 155
  • [8] A role-involved purpose-based access control model
    Md. Enamul Kabir
    Hua Wang
    Elisa Bertino
    Information Systems Frontiers, 2012, 14 : 809 - 822
  • [9] A role-involved purpose-based access control model
    Kabir, Md Enamul
    Wang, Hua
    Bertino, Elisa
    INFORMATION SYSTEMS FRONTIERS, 2012, 14 (03) : 809 - 822
  • [10] Towards Application-Layer Purpose-Based Access Control
    Pallas, Frank
    Ulbricht, Max-R
    Tai, Stefan
    Peikert, Thomas
    Reppenhagen, Marcel
    Wenzel, Daniel
    Wille, Paul
    Wolf, Karl
    PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1288 - 1296