• DocumentCode
    2297831
  • Title

    A Customer-Centric Privacy Protection Framework for Mobile Service-Oriented Architectures

  • Author

    Cheng, Winnie ; Li, Jun ; Moore, Keith ; Karp, Alan H.

  • Author_Institution
    Massachusetts Inst. of Technol., Cambridge, MA
  • Volume
    2
  • fYear
    2008
  • fDate
    7-11 July 2008
  • Firstpage
    13
  • Lastpage
    20
  • Abstract
    Mobile companions such as smart phones and PDAs carry a lot of sensitive data about their owners. With new services aimed at providing more targeted information retrieval through increased interactions with these devices, privacy concerns of individuals must be addressed. Existing mobile service computing solutions give users little control over the release of this information. In this paper, we present a privacy-aware information brokerage framework called MUPPET that incorporates three novel techniques to give users control over the release of their data. First, it introduces operation-focused access control, a purpose-based access control model that supports flexible and fine-grain policies using typed operation labels. Second, MUPPET includes a purpose detector that has a number of techniques to detect the active purpose in a pervasive environment. Third, our system allows reward-driven information exchange, a protocol for explicit communication and negotiation of justifications and rewards supporting tunable privacy policies based on ongoing evaluation of the information exchange. To validate our design, the MUPPET prototype has been integrated with a personalized coupon offering application for two different service providers in an experimental retail kiosk setting.
  • Keywords
    authorisation; data privacy; information retrieval; mobile computing; MUPPET prototype; customer-centric privacy protection; fine-grain policies; information retrieval; mobile service computing; mobile service-oriented architectures; operation-focused access control; pervasive environment; privacy-aware information brokerage; purpose detector; purpose-based access control; retail kiosk; reward-driven information exchange; tunable privacy policies; Access control; Access protocols; Detectors; Information retrieval; Mobile computing; Personal digital assistants; Privacy; Protection; Service oriented architecture; Smart phones; Access Control; Mobile Computing; Privacy; Service-Oriented Architectures;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services Computing, 2008. SCC '08. IEEE International Conference on
  • Conference_Location
    Honolulu, HI
  • Print_ISBN
    978-0-7695-3283-7
  • Type

    conf

  • DOI
    10.1109/SCC.2008.111
  • Filename
    4578504