• DocumentCode
    1732052
  • Title

    Towards Unconditional Anonymity: Privacy Enforcement Model in Web Services

  • Author

    Yang, Yong ; Yang, Jian

  • Author_Institution
    Dept. of Comput., Macquarie Univ., Park Sydney, NSW
  • fYear
    2008
  • Firstpage
    26
  • Lastpage
    33
  • Abstract
    Privacy in Web services is of great importance and a critical requirement for any business and non-business environments. The growth of Web services has been accompanied by sharing more and more user personal information with Web service providers between diverse and heterogeneous computing systems, which has raised concern about possible malicious or accidental unauthorized abuse of user information. The security assertion markup language (SAML) architecture is an XML standard for exchanging authentication and authorization data. However privacy preserving in SAML is inadequate for user privacy protection. In this paper, the SAML architecture is extended to address this shortcoming. A privacy enforcement model-based on ring signature is presented, which provides unconditional anonymity for Web service users. This model enables verification of individuals who belong to a specific group with access right without actually being identified by their IDs or names. Therefore the risk of information leak is reduced. Furthermore, even if the third party is corrupted or the ID correspondence relationship is leaked, the individual remains unrecognizable. Meanwhile most SAML authorization between individual and web services can be done without the presence of the third party, which largely decreases communication overhead and enhances the privacy. Finally, a web services conversation establishment protocol is constructed based on this model, which has been implemented in Java/Tomcat.
  • Keywords
    Web services; XML; security of data; software architecture; Java/Tomcat; Web services; XML; authentication data; authorization data; heterogeneous computing systems; privacy enforcement model; security assertion markup language architecture; unconditional anonymity; user privacy protection; Authentication; Authorization; Computer architecture; Data security; Information security; Markup languages; Privacy; Protection; Web services; XML; Web services; privacy; unconditional anonymity;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Congress on Services Part II, 2008. SERVICES-2. IEEE
  • Conference_Location
    Beijing
  • Print_ISBN
    978-0-7695-3313-1
  • Electronic_ISBN
    978-0-7695-3313-1
  • Type

    conf

  • DOI
    10.1109/SERVICES-2.2008.8
  • Filename
    4700496