• DocumentCode
    3345574
  • Title

    Achieving Data Privacy and Security Using Web Services

  • Author

    Weaver, Alfred C.

  • Author_Institution
    University of Virginia, e-mail: acw@cs.virginia.edu
  • fYear
    2005
  • fDate
    14-17 Dec. 2005
  • Abstract
    The Internet has proven to be a powerful enabler for anywhere/anytime access to data and software located through the world. The downside of this capability is that it exposes these resources to information leakage, malicious invasion by hackers, and damage due to software viruses. This risk can be mitigated by the intelligent use of a web services architecture than can enforce both data privacy and security. In this talk I will propose a security architecture that enforces information security by addressing the key issues of authentication, authorization, and federation. Authentication results in a security token that conveys both the identity of the requestor and the trust level of the identification technology. Authorization determines what objects are accessible by a user given his identity token, request, role, context, and privileges. Federation, using both direct and indirect trust, addresses the problem of how identity, once legitimately established in one trust domain, can be reliably exported to another cooperating trust domain. I will discuss our implementation of these ideas in an on-going research project to protect medical data, and will illustrate how the concepts generalize to protect arbitrary data resources.
  • Keywords
    Authentication; Authorization; Computer architecture; Computer hacking; Data privacy; Data security; Information security; Internet; Protection; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Industrial Technology, 2005. ICIT 2005. IEEE International Conference on
  • Print_ISBN
    0-7803-9484-4
  • Type

    conf

  • DOI
    10.1109/ICIT.2005.1600869
  • Filename
    1600869