• DocumentCode
    2066060
  • Title

    Design and implementation of virtual private services

  • Author

    Ioannidis, Sotiris ; Bellovin, Steven M. ; Ioannidis, John ; Keromytis, Angelos D. ; Smith, Jonathan M.

  • Author_Institution
    Pennsylvania Univ., PA, USA
  • fYear
    2003
  • fDate
    9-11 June 2003
  • Firstpage
    269
  • Lastpage
    274
  • Abstract
    Large scale distributed applications such as electronic commerce and online marketplaces combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, which are exacerbated by the complexity of the operating environment. In order to handle policies at multiple locations, the usual tools available (firewalls and compartmented file storage) get to be used in ways that are clumsy and prone to failure. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy. Second, we create virtual security domains, each with its own security policy. Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points. We describe our architecture and a prototype implementation, and present a preliminary performance evaluation confirming that our overhead of policy enforcement using is small.
  • Keywords
    multicast protocols; performance evaluation; security of data; software architecture; virtual private networks; architecture; computational element; distributed applications; electronic commerce; global security policy; local autonomy; multiple storage; network access; online marketplaces; operating environment complexity; performance evaluation; permissions; policy enforcement; policy handling; privacy issue; privileges; prototype implementation; resource control; security issue; split policy specification; virtual security domain; Access control; Application software; Credit cards; Electronic commerce; File servers; Large-scale systems; Privacy; Security; Transaction databases; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Enabling Technologies: Infrastructure for Collaborative Enterprises, 2003. WET ICE 2003. Proceedings. Twelfth IEEE International Workshops on
  • ISSN
    1080-1383
  • Print_ISBN
    0-7695-1963-6
  • Type

    conf

  • DOI
    10.1109/ENABL.2003.1231419
  • Filename
    1231419