Protecting Consumer Data in Composite Web Services

Protecting Consumer Data in Composite Web Services
复制标题

保护复合 Web 服务中的消费者数据

DOI:
10.1007/0-387-25660-1_2
复制
发表时间:
2005
期刊:
IEICE Trans. Commun.
影响因子:
--
通讯作者:
R. V. Schyndel
R. V. Schyndel
中科院分区:
--
文献类型:
--
作者:
C. Pearce;P. Bertók;R. V. Schyndel

文献摘要

被引文献

相似文献

越来越多的供应商运营的数据库对客户隐私和安全入侵构成了独特的威胁,因为在线交易中传递的个人信息可能被供应商滥用。现有的隐私增强技术在供应商违反其声明的隐私政策的情况下失败,导致客户隐私和安全的损失。当交易需要识别参与者时,匿名性可能不适用。我们提出了一个面向服务的技术上可执行的系统,保护隐私和安全的客户与不可信的在线供应商进行交易。该系统扩展到多个供应商在复合Web服务中交互时支持客户隐私保护。引入了半可信处理器,以便在受保护的环境中安全执行敏感的客户信息,并在有争议的交易中提供问责制。
The increasing number of linkable vendor-operated databases present unique threats to customer privacy and security intrusions, as personal information communicated in online transactions can be misused by the vendor. Existing privacy enhancing technologies fail in the event of a vendor operating against their stated privacy policy, leading to loss of customer privacy and security. Anonymity may not be applicable when transactions require identification of participants. We propose a service-oriented technically enforceable system that preserves privacy and security for customers transacting with untrusted online vendors. The system extends to support protection of customer privacy when multiple vendors interact in composite web services. A semi-trusted processor is introduced for safe execution of sensitive customer information in a protected environment and provides accountability in the case of disputed transactions.