DocumentCode :
3345574
Title :
Achieving Data Privacy and Security Using Web Services
Author :
Weaver, Alfred C.
Author_Institution :
University of Virginia, e-mail: acw@cs.virginia.edu
fYear :
2005
fDate :
14-17 Dec. 2005
Abstract :
The Internet has proven to be a powerful enabler for anywhere/anytime access to data and software located through the world. The downside of this capability is that it exposes these resources to information leakage, malicious invasion by hackers, and damage due to software viruses. This risk can be mitigated by the intelligent use of a web services architecture than can enforce both data privacy and security. In this talk I will propose a security architecture that enforces information security by addressing the key issues of authentication, authorization, and federation. Authentication results in a security token that conveys both the identity of the requestor and the trust level of the identification technology. Authorization determines what objects are accessible by a user given his identity token, request, role, context, and privileges. Federation, using both direct and indirect trust, addresses the problem of how identity, once legitimately established in one trust domain, can be reliably exported to another cooperating trust domain. I will discuss our implementation of these ideas in an on-going research project to protect medical data, and will illustrate how the concepts generalize to protect arbitrary data resources.
Keywords :
Authentication; Authorization; Computer architecture; Computer hacking; Data privacy; Data security; Information security; Internet; Protection; Web services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Industrial Technology, 2005. ICIT 2005. IEEE International Conference on
Print_ISBN :
0-7803-9484-4
Type :
conf
DOI :
10.1109/ICIT.2005.1600869
Filename :
1600869
Link To Document :
بازگشت