Negotiated Security Policies for E-Services and Web Services

  • Authors:
  • George Yee;Larry Korba

  • Affiliations:
  • Institute for Information Technology;Institute for Information Technology

  • Venue:
  • ICWS '05 Proceedings of the IEEE International Conference on Web Services
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

The growth of the Internet has been accompanied by the growthof e-services (e.g. e-commerce, ehealth). This proliferation of e- services and the increasing attacks on them by malicious individuals have highlighted the need for e-service security. The securityrequirements of an e-service may be specified in an e-servicesecurity policy. The provider of the eservice is then responsiblefor implementing the security measures contained in the policy.However, a service consumer may have security preferences that are not reflected in the providerýs e-service security policy (e.g.defense contractors may require higher levels of security). In orderfor service providers to reach a wider market, a way of customizinga security policy to a particular consumer is needed. We derive the content of an e-service security policy and propose a flexibleapproach that will allow an e-service provider and consumer tonegotiate to an agreed-upon e-service security policy. In addition,we examine how our approach may be implemented in a WebServices environment and briefly describe the design of our security policy negotiation prototype.