首页> 外文会议>IEEE International Conference on Web Services >Privacy Preserving Access Control in Service-Oriented Architecture
【24h】

Privacy Preserving Access Control in Service-Oriented Architecture

机译:隐私保留在面向服务的架构中的访问控制

获取原文

摘要

Service-oriented Architecture (SOA) comprises a number of loosely-coupled independent services, which collaborate, interact and share data to accomplish incoming requests. A service invocation can involve multiple services, where each service accesses, processes and shares the client's data. These interactions may share data with unauthorized services and violate client's privacy. The client has no means of identifying if a violation occurred because it has no control over the service invocations beyond its trust domain. Such interactions introduce new security challenges which are not present in traditional systems. This paper proposes a data-centric approach for privacy preserving access control in SOA. Benefits of the proposed approach include the ability to dynamically define access polices by the clients and control data access at the time of each service interaction. A realistic healthcare scenario is used to evaluate the implementation of the proposed solution which validates its viability.
机译:面向服务的架构(SOA)包括许多松散耦合的独立服务,它协作,交互和共享数据以完成传入请求。服务调用可以涉及多个服务,其中每个服务访问,进程和共享客户端的数据。这些互动可以与未经授权的服务共享数据并违反客户的隐私。客户端没有识别违规是否发生了违规,因为它无法控制超出其信任域之外的服务调用。这种互动引入了传统系统中不存在的新安全挑战。本文提出了一种在SOA中保留访问控制的数据为中心的方法。所提出的方法的好处包括能够通过客户端动态定义访问策略并在每个服务交互时控制数据访问。现实的医疗保健方案用于评估所提出的解决方案的实施,验证其可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号