Metamodel for Privacy Policies within SOA

被引:6
作者
Allison, David S. [1 ]
El Yamany, Hany F. [1 ]
Capretz, Miriam A. M. [1 ]
机构
[1] Univ Western Ontario, Dept Elect & Comp Engn, Fac Engn, London, ON N6A 5B9, Canada
来源
2009 ICSE WORKSHOP ON SOFTWARE ENGINEERING FOR SECURE SYSTEMS | 2009年
关键词
D O I
10.1109/IWSESS.2009.5068457
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
As Service-Oriented Architecture (SOA) continues to grow as a viable approach to systems development, so too does the number of services available. The strength of services in an SOA environment to provide interoperability comes at the cost of reduced privacy, as more interactions between autonomous services require more information to be exchanged In this paper we define a metamodel for privacy policy creation and comparison based on fair information practices introduced around the world to protect the privacy of individuals. We develop criteria for the comparison of the elements that compose the policies, creating hierarchical relationships between those elements that could not otherwise be directly compared. An example of two policies being compared is presented to demonstrate how this comparison can be done. We believe this definition of how to create and compare privacy policies forms a strong foundation from which a comprehensive solution to SOA privacy can be built.
引用
收藏
页码:40 / 46
页数:7
相关论文
共 15 条
[1]  
[Anonymous], 2019, EDPS Guidelines on Assessing the Proportionality of Measures that Limit the Fundamental Rights to Privacy and to the Protection of Personal Data
[2]   P3P adoption on E-commerce web sites - A survey and analysis [J].
Beatty, Patricia ;
Reay, Ian ;
Dick, Scott ;
Miller, James .
IEEE INTERNET COMPUTING, 2007, 11 (02) :65-71
[3]  
BENNETT C, 1997, GOVT INFORM Q, V1, P351
[4]  
*CAN STAND ASS, 1996, CAN STAND ASS MOD CO
[5]  
Cavoukian A., 2002, PRIVACY PAYOFF SUCCE
[6]  
Cranor Lorrie, 2002, The Platform for Privacy Preferences 1.0 (P3P1.0) Specification
[7]  
GUERMOUCHE N, 2007, IEEE INT C WEB SERV
[8]  
Kanneganti R., 2008, SOA SECURITY
[9]  
*OFF SEC MAN SAF, 2003, FURTH AM EO 12958 AM
[10]   Service-oriented solution framework for internet banking [J].
Shan, Tony Chao ;
Hua, Winnie Wei .
INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2006, 3 (01) :29-48