Purpose-Based Privacy Preserving Access Control for Secure Service Provision and Composition

被引:21
|
作者
Amini, Morteza [1 ]
Osanloo, Farnaz [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran 1136511155, Iran
关键词
Cloud computing; software as a service; service composition; access control; privacy preserving; CLOUD; MECHANISM;
D O I
10.1109/TSC.2016.2616875
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Two main security issues in software as a service (SaaS) delivery model of cloud environments are access control and privacy preserving in basic web services as well as composite services where we require to infer policies through the automatic composition of the policies specified for their constituting basic services. In this paper, we present a privacy preserving access control model and framework for secure service provision and composition. The model is a combination of an attribute based access control model and a proposed purpose-based privacy model. Following this model, an access request for a service is permitted if the requester's attribute certificates and contextual conditions are in compliance with the access control policies specified by the service provider and simultaneously the privacy preferences of the requester is compatible with the privacy policies of the service provider. In the framework proposed in this paper, for secure service composition, possible chains of composite services are ranked according to the users' preferences and sensitivity level of their data. The security policies of the composite service, established by the chosen chain of services, are inferred by automatic composition of policies specified for the basic services in the chain.
引用
收藏
页码:604 / 620
页数:17
相关论文
共 50 条
  • [41] A secure privacy preserving and access control scheme for medical internet of things (MIoT) using attribute-based signcryption
    Patil R.Y.
    International Journal of Information Technology, 2024, 16 (1) : 181 - 191
  • [42] Privacy-preserving location-based service protocols with flexible access
    Tang, Shuyang
    Liu, Shengli
    Huang, Xinyi
    Liu, Zhiqiang
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2019, 20 (03) : 412 - 423
  • [43] Realizing Purpose-Based Privacy Policies Succinctly via Information-Flow Labels
    Kumar, N. V. Narendra
    Shyamasundar, R. K.
    2014 IEEE FOURTH INTERNATIONAL CONFERENCE ON BIG DATA AND CLOUD COMPUTING (BDCLOUD), 2014, : 753 - 760
  • [44] SePCAR: A Secure and Privacy-Enhancing Protocol for Car Access Provision
    Symeonidis, Iraklis
    Aly, Abdelrahaman
    Mustafa, Mustafa Asan
    Mennink, Bart
    Dhooghe, Siemen
    Preneel, Bart
    COMPUTER SECURITY - ESORICS 2017, PT II, 2017, 10493 : 475 - 493
  • [45] A situation-aware access control based privacy-preserving service matchmaking approach for Service-Oriented Architecture
    Yau, Stephen S.
    Liu, Junwei
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 1056 - +
  • [46] Efficient Enforcement of Action-aware Purpose-based Access Control within Relational Database Management Systems
    Colombo, Pietro
    Ferrari, Elena
    2016 32ND IEEE INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2016, : 1516 - 1517
  • [47] A privacy preserving access control mechanism for network-based database
    Rui, Fan
    2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 3, 2008, : 435 - 439
  • [48] Trust Based Privacy Preserving Access Control In Web Services Paradigm
    Bhatia, Rekha
    Singh, Manpreet
    2013 SECOND INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, NETWORKING AND SECURITY (ADCONS 2013), 2013, : 243 - 246
  • [49] Token based Privacy Preserving Access Control in Wireless Sensor Networks
    Tanuja, R.
    Shruthi, Y. R.
    Manjula, S. H.
    Venugopal, K. R.
    Patnaik, L. M.
    2015 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATIONS (ADCOM), 2015, : 45 - 50
  • [50] The Location Privacy Preserving of Social Network Based on RCCAM Access Control
    Zhang, Xueqin
    Zhou, Qianru
    Gu, Chunhua
    Han, Liangxiu
    IETE TECHNICAL REVIEW, 2018, 35 : 68 - 75