EPICS: A Framework for Enforcing Security Policies in Composite Web Services


Creative Commons License

Ranchal R., Bhargava B., ANGIN P., ben Othmane L.

IEEE TRANSACTIONS ON SERVICES COMPUTING, cilt.12, sa.3, ss.415-428, 2019 (SCI-Expanded) identifier identifier

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 12 Sayı: 3
  • Basım Tarihi: 2019
  • Doi Numarası: 10.1109/tsc.2018.2797277
  • Dergi Adı: IEEE TRANSACTIONS ON SERVICES COMPUTING
  • Derginin Tarandığı İndeksler: Science Citation Index Expanded (SCI-EXPANDED), Scopus
  • Sayfa Sayıları: ss.415-428
  • Anahtar Kelimeler: Cloud computing, composite web services, active bundles, security, privacy, access control, INFORMATION
  • Orta Doğu Teknik Üniversitesi Adresli: Evet

Özet

With advances in cloud computing and the emergence of service marketplaces, the popularity of composite services marks a paradigm shift from single-domain monolithic systems to cross-domain distributed services, which raises important privacy and security concerns. Access control becomes a challenge in such systems because authentication, authorization and data disclosure may take place across endpoints that are not known to clients. The clients lack options for specifying policies to control the sharing of their data and have to rely on service providers which offer limited selection of security and privacy preferences. This lack of awareness and loss of control over data sharing increases threats to a client's data and diminishes trust in these systems. We propose EPICS, an efficient and effective solution for enforcing security policies in composite Web services that protects data privacy throughout the service interaction lifecycle. The solution ensures that the data are distributed along with the client policies that dictate data access and an execution monitor that controls data disclosure. It empowers data owners with control of data disclosure decisions during interactions with remote services and reduces the risk of unauthorized access. The paper presents the design, implementation, and evaluation of the EPICS framework.