Preserving Privacy in Dynamic Web Service Composition

نویسندگان

  • Dieter Hutter
  • Melanie Volkamer
چکیده

The proliferation of web services as self-contained web accessible programs and the idea of the Semantic Web of making information computer-interpretable enables the dynamic composition of complex services assembled from various individual services and typically distributed over the web. Following the paradigm of pervasive computing, pro-active agents are installed on mobile phones or PDAs operating on the web and handle the context-aware discovery of appropriate services and use AI-based plan generation techniques to dynamically compose the retrieved service to solve complex tasks. Functional composition of complex services is well understood and supported. However, the introduction of web services in general and dynamic web service composition (e.g. [2, 7]) in particular requires appropriate security facilities to guarantee the security requirements of all participants. On the one hand, web services have to be protected against misuse of their resources, and on the other hand, the user of web services require the privacy of their data. Standard approaches for secure execution of services such as those using REI [6] or Ponder [3] are based on the specification of access control policies to control the individual execution of services and thus focus on the first task. We propose an approach [4, 5] to ensure the privacy of user data by introducing a dynamic security check between plan generation and execution of the plan. Thereby we can guarantee that the execution of a synthesized plan will not distribute user's or newly generated data to a non-entitled web service. We make use of techniques developed in program language security in general and an adapted version of Volpano Smith's [8, 9] security type calculus in particular. To protect the privacy of user related information, the data used in web services is always classified according to its confidentiality. Web services require the corresponding clearances to deal with confidential data. Both classifications and clearances are denoted by a so-called security types. There is a partial ordering ≤ on security types which allow us to compare them. The set of all security types together with ≤ forms a lattice. Similar to the approach presented by Bell and La-Padula [1], the idea is that a web service is only entitled to obtain a specific datum if its clearance is at least as high as the classification of the data. However, in practice we would like to select the clearances of web services and also the classification of data with respect to …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Privacy Preserving Enhanced Trust Building Mechanism for Web Services

With the development of web services, more effective trust building mechanisms are needed to deploy diverse trust models in a web services environment. The lack of mechanisms that can dynamically build trust relationships while preserving privacy impedes progress. Current web service technologies encourage a client to reveal all its private attributes in a pre-packaged digital credential to the...

متن کامل

Privacy enhanced and web based service composition

Service selection is a key issue in the Future Internet ,where applications are built by composing services and content service providers. The Most existing service selection of schemas only focus on the functional QoS By contrast, the risk of privacy breaches arising properties of the services such as throughput, latency and response time, or on their trust and reputation level. From selection...

متن کامل

An SOA-Based Architecture to Share Medical Data with Privacy Preservation

Recent years have witnessed a growing interest in using Web services as a reliable means for medical data sharing inside and across healthcare organizations. In such service-based data sharing environments, Web service composition emerged as a viable approach to query data scattered across independent locations. Patient data privacy preservation is an important aspect that must be considered wh...

متن کامل

Privacy-Enhanced Web Service Composition

Data as a Service (DaaS) builds on service-oriented technologies to enable fast access to data resources on the Web. However, this paradigm raises several new privacy concerns that traditional privacy models do not handle. In addition, DaaS composition may reveal privacysensitive information. In this paper, we propose a formal privacy model in order to extend DaaS descriptions with privacy capa...

متن کامل

Privacy-Aware DaaS Services Composition

Data as a Service (DaaS) builds on service-oriented technologies to enable fast access to data resources on the Web. However, this paradigm raises several new privacy concerns that traditional privacy models do not handle since they only focus on the service interface without taking into account privacy constraints related to the data exchanged with a DaaS during its invocation. In addition, Da...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006