Minimal privacy authorization in web services collaboration

  • Authors:
  • Linyuan Liu;Haibin Zhu;Zhiqiu Huang;Dongqing Xie

  • Affiliations:
  • College of Information Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China;Department of Computer Science and Mathematics, Nipissing University, Ontario, Canada;College of Information Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China;College of Computer Science, Guangzhou University, Guangzhou, China

  • Venue:
  • Computer Standards & Interfaces
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

With the popularity of Internet technology, web services are becoming the most promising paradigm for distributed computing. This increased use of web services has meant that more and more personal information of consumers is being shared with web service providers, leading to the need to guarantee that the private data of consumers are not illegitimate collected, used and disclosed in services collaboration. This paper studies how to realize the minimal privacy authorization while achieving the functional goals. Initially, this paper uses authorization policies to specify the privacy privileges of the services collaboration, and utilizes the trust relationships among services to make authorization decision. Next, it models the interface behaviors of services by extending the interface automata to support privacy semantics. Furthermore, it quantitatively analyzes the minimum set of privacy privileges which are required by the services to achieve the functional goals, and presents the minimal authorization algorithm, which helps us to automatically derive optimal authorization policies for a services collaboration. Finally, it verifies the correctness and efficiency of the approach proposed by this paper through a case study.