DocumentCode
3345574
Title
Achieving Data Privacy and Security Using Web Services
Author
Weaver, Alfred C.
Author_Institution
University of Virginia, e-mail: acw@cs.virginia.edu
fYear
2005
fDate
14-17 Dec. 2005
Abstract
The Internet has proven to be a powerful enabler for anywhere/anytime access to data and software located through the world. The downside of this capability is that it exposes these resources to information leakage, malicious invasion by hackers, and damage due to software viruses. This risk can be mitigated by the intelligent use of a web services architecture than can enforce both data privacy and security. In this talk I will propose a security architecture that enforces information security by addressing the key issues of authentication, authorization, and federation. Authentication results in a security token that conveys both the identity of the requestor and the trust level of the identification technology. Authorization determines what objects are accessible by a user given his identity token, request, role, context, and privileges. Federation, using both direct and indirect trust, addresses the problem of how identity, once legitimately established in one trust domain, can be reliably exported to another cooperating trust domain. I will discuss our implementation of these ideas in an on-going research project to protect medical data, and will illustrate how the concepts generalize to protect arbitrary data resources.
Keywords
Authentication; Authorization; Computer architecture; Computer hacking; Data privacy; Data security; Information security; Internet; Protection; Web services;
fLanguage
English
Publisher
ieee
Conference_Titel
Industrial Technology, 2005. ICIT 2005. IEEE International Conference on
Print_ISBN
0-7803-9484-4
Type
conf
DOI
10.1109/ICIT.2005.1600869
Filename
1600869
Link To Document