Obligations of trust for privacy and confidentiality in distributed transactions
نویسندگان
چکیده
Purpose – This paper describes a bilateral symmetric approach to authorization, privacy protection and obligation enforcement in distributed transactions. We introduce the concept of the Obligation of Trust (OoT) protocol as a privacy assurance and authorization mechanism that is built upon the XACML standard. The OoT allows two communicating parties to dynamically exchange their privacy and authorization requirements and capabilities, which we term a Notification of Obligation (NoB), as well as their commitments to fulfilling each others requirements, which we term Signed Acceptance of Obligations (SAO). We describe some applicability of these concepts and show how they can be integrated into distributed authorization systems for stricter privacy and confidentiality control. Design/Methodology/Approach – Existing access control and privacy protection systems are typically unilateral and provider-centric, in that the enterprise service provider assigns the access rights, makes the access control decisions, and determines the privacy policy. There is no negotiation between the client and the service provider about which access control or privacy policy to use. We adopt a symmetric, more user-centric approach to privacy protection and authorization, which treats the client and service provider as peers, in which both can stipulate their requirements and capabilities, and hence negotiate terms which are equally acceptable to both parties. Findings – We demonstrate how the Obligation of Trust protocol can be used in a number of different scenarios to improve upon the mechanisms that are currently available today. Practical Implications – This approach will serve to increase trust in distributed transactions since each communicating party receives a difficult to repudiate digitally signed Acceptance of Obligations, in a standard language (XACML), which can be automatically enforced by their respective computing machinery. Originality/Value – This paper adds to current research in trust negotiation, privacy protection and authorization by combining all three together into one set of standardized protocols. Furthermore, by providing hard to repudiate Signed Acceptance of Obligations messages, this strengthens the legal case of the injured party should a dispute arise.
منابع مشابه
Obligations for Privacy and Confidentiality in Distributed Transactions
Existing access control systems are typically unilateral in that the enterprise service provider assigns the access rights and makes the access control decisions, and there is no negotiation between the client and the service provider. As access management systems lean towards being user-centric, unilateral approaches can no longer adequately preserve the user’s privacy, particularly where the ...
متن کاملStudy of Healthcare Service Recipients' Perceptions Regarding Observance of Patient Privacy and Medical Confidentiality in Teaching Healthcare Centers Affiliated with the Qom University of Medical Sciences in 2015-2016, Iran
Background and Objectives: Medical confidentiality and maintenance of patient personal privacy are considered two important moral obligations in medical ethics with a long history in medicine. To be efficient, a healthcare system needs active participation of and appropriate cooperation between the recipients and providers of healthcare services. This study was conducted to investigate healthca...
متن کاملTrust Management for E-Transactions
There has been an enormous increase of transactions and cooperative-computing services on the Internet. This is both a technical and a social phenomenon. Transactions and services over the Internet have global reach and users, known or unknown to the service provider, might be interested in availing the access or participate in the cooperative transaction in a distributed manner. Thus, it is ve...
متن کاملThe Tension between Transparency and Confidentiality in International Arbitrations
The present research study intends to investigate the concepts of transparency, confidentiality and privacy within the scope of Investor-State Arbitration and International Commercial Arbitration.Transparency, confidentiality and privacy are the main pillars of international arbitration which have a close relationship together, however in some cases they are in a controversial situation. The te...
متن کاملTrustworthy Web Services: An Experience-Based Model for Trustworthiness Evaluation
Recent Articles: n Trustworthy Web Services: An Experience-Based Model for Trustworthiness Evaluation n Administering the Semantic Web: Confidentiality, Privacy, and Trust Management n Privacy-Preserving Transactions Protocol using Mobile Agents with Mutual Authentication As information technology and the Internet become increasingly pervasive in our daily lives, there is an essential need for ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Internet Research
دوره 19 شماره
صفحات -
تاریخ انتشار 2009