Purpose-Based Privacy Preserving Access Control for Secure Service Provision and Composition

被引:21
|
作者
Amini, Morteza [1 ]
Osanloo, Farnaz [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran 1136511155, Iran
关键词
Cloud computing; software as a service; service composition; access control; privacy preserving; CLOUD; MECHANISM;
D O I
10.1109/TSC.2016.2616875
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two main security issues in software as a service (SaaS) delivery model of cloud environments are access control and privacy preserving in basic web services as well as composite services where we require to infer policies through the automatic composition of the policies specified for their constituting basic services. In this paper, we present a privacy preserving access control model and framework for secure service provision and composition. The model is a combination of an attribute based access control model and a proposed purpose-based privacy model. Following this model, an access request for a service is permitted if the requester's attribute certificates and contextual conditions are in compliance with the access control policies specified by the service provider and simultaneously the privacy preferences of the requester is compatible with the privacy policies of the service provider. In the framework proposed in this paper, for secure service composition, possible chains of composite services are ranked according to the users' preferences and sensitivity level of their data. The security policies of the composite service, established by the chosen chain of services, are inferred by automatic composition of policies specified for the basic services in the chain.
引用
收藏
页码:604 / 620
页数:17
相关论文
共 50 条
  • [31] Purpose-Based Information Flow Control for Cyber Engineering
    Enokido, Tomoya
    Takizawa, Makoto
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2011, 58 (06) : 2216 - 2225
  • [32] An Integrated Privacy Preserving Attribute Based Access Control Framework
    Xu, Runhua
    Joshi, James B. D.
    PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 68 - 76
  • [33] Location Based Privacy Preserving Access Control for Relational Data
    Lakadkutta, Ahmed H. I.
    Mante, R. V.
    2016 IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2016, : 2083 - 2087
  • [34] HECC based Patient Privacy Preserving Access Control Model
    Prasanalakshmi, B.
    Pugalendhi, Ganesh Kumar
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2019, 19 (03): : 50 - 53
  • [35] Purpose fusion: The risk purpose based privacy-aware data access control
    Liu Y.-M.
    Zhou H.-F.
    Wang Z.-H.
    Wang W.
    Jisuanji Xuebao/Chinese Journal of Computers, 2010, 33 (08): : 1339 - 1348
  • [36] PrSChain: A Blockchain Based Privacy Preserving Approach for Data Service Composition
    Khemaissia R.
    Derdour M.
    Ferrag M.A.
    Bouhamed M.M.
    Informatica (Slovenia), 2023, 47 (09): : 91 - 108
  • [37] Privacy-preserving ID-based service provision in ubiquitous computing environments
    Lee, KM
    Lee, SH
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2004: OTM 2004 WORKSHOPS, PROCEEDINGS, 2004, 3292 : 21 - 22
  • [38] Purpose based access control for privacy protection in relational database systems
    Ji-Won Byun
    Ninghui Li
    The VLDB Journal, 2008, 17 : 603 - 619
  • [39] Purpose based access control for privacy protection in relational database systems
    Byun, Ji-Won
    Li, Ninghui
    VLDB JOURNAL, 2008, 17 (04): : 603 - 619
  • [40] Towards differential access control and privacy-preserving for secure media data sharing in the cloud
    Zheng, Tengfei
    Luo, Yuchuan
    Zhou, Tongqing
    Cai, Zhiping
    COMPUTERS & SECURITY, 2022, 113