Conceptual Modeling of Privacy-Aware Web Service Protocols
2007, Lecture Notes in Computer Science
https://doi.org/10.1007/978-3-540-72988-4_17Abstract
Internet users are becoming increasingly concerned about their personal information being collected and used by Web service providers. They want to ensure that it is stored and used according to the providers' privacy policies. Since these policies are mainly developed and maintained separately from the business process that collects and manipulates data, it is hard to perform analysis and management of the processes in terms of privacy policies. To address this problem, we propose a formal technique with which Web service providers describe the use and storage of personal data. The description is integrated with a Web service protocol using an extended state machine model. Having such a conceptual model will enable model-driven development and management of Web service protocols with respect to their privacy aspects such as collection, disclosure, and obligation. A tool support has been implemented, as part of ServiceMosaic, to let designers model privacy aspects within the Web service protocol.
References (17)
- Curbera, F., Duftler, M., Khalaf, R., Nagy, W., Mukhi, N., Weerawarana, S.: Unraveling the Web Services Web: An Introduction to SOAP, WSDL, and UDDI. IEEE Internet Computing 6(2) (2002) 86-93
- Curbera, F., Goland, Y., Klein, J., Leymann, F., Roller, D., Thatte, S., Weerawarana, S.: Business Process Execution Language for Web Services (BPEL4WS). http://dev2dev.bea.com/techtrack/ BPEL4WS.jsp (2002)
- Benatallah, B., Casati, F., Toumani, F., Hamadi, R.: Conceptual Modeling of Web Service Con- versations. In: Proceedings of the 15th International Conference on Advanced Information Systems Engineering (CAiSE'03). LNCS 2681, Klagenfurt, Austria, Springer (2003) 449-467
- Benatallah, B., Casati, F., Ponge, J., Toumani, F.: On Temporal Abstractions of Web Service Protocols. In: CAiSE'05 Short Paper Proceedings, Porto, Portugal (2005)
- Cranor, L., Langheinrich, M., Marchiori, M., Presler-Marshall, M., , Reagle, J.: The Platform for Privacy Preferences 1.0 (P3P1.0) Specification. W3C Recommendation (2002)
- Ashley, P., Hada, S., Karjoth, G., Powers, C., Schunter, M.: Enterprise Privacy Authorization Lan- guage (EPAL 1.1) Specification. IBM Research Report. http://www.zurich.ibm.com/security/ enterprise-privacy/epal (2003)
- Amazon.com: Amazon.com Privacy Notice. http://www.amazon.com/gp/help/customer/display. html?nodeId=468496 (2006)
- Cranor, L.F.: Web Privacy with P3P. O'Reilly (2002)
- Clark, J., DeRose, S.: XML Path Language (XPath) Version 1.0. http://www.w3.org/TR/xpath (1999)
- Benatallah, B., Casati, F., Toumani, F., Ponge, J., Motahari Nezhad, H.: Service Mosaic: A Model- Driven Framework for Web Services Life-Cycle Management. IEEE Internet Computing 10(4) (2006) 55-63
- Benatallah, B., Casati, F., Toumani, F.: Representing, Analysing and Managing Web Service Protocols. Data and Knowledge Engineering 58(3) (2006) 327-357
- Yu, T., Li, N., Antón, A.: A Formal Semantics for P3P. In: Proceedings of the 2004 Workshop on Secure Web Wervice (SWS'04), Fairfax, USA, ACM (2004) 1-8
- Karjoth, G., Schunter, M., Herreweghen, E.: Translating Privacy Practices into Privacy Promises -How to Promise What You Can Keep. In: Proceedings of the 4th IEEE International Workshop on Policies for Distributed Systems and Networks (POLICY'03), Lake Como, Italy, IEEE Computer Society (2003) 135-146
- Egelman, S., Cranor, L., Chowdhury, A.: An analysis of P3P-Enabled Web Sites Among Top-20 Search Results. In: Proceedings of the 8th International Conference on Electronic Commerce (ICEC'06), Fredericton, Canada, ACM (2006) 197-207
- Levy, S., Gutwin, C.: Improving Understanding of Website Privacy Policies with Fine-Grained Policy Anchors. In: Proceedings of the 14th International Conference on World Wide Web (WWW'05), Chiba, Japan, ACM (2005) 480-488
- Agrawal, R., Kiernan, J., Srikant, R., Xu, Y.: Hippocratic Databases. In: Proceedings of the 28th International Conference on Very Large Data Bases (VLDB'02), Hong Kong, China, Morgan Kaufmann (2002) 143-154
- Rezgui, A., Ouzzani, M., Bouguettaya, A., Medjahed, B.: Preserving Privacy in Web Services. In: Proceedings of the 4th ACM CIKM International Workshop on Web Information and Data Management (WIDM'02), Virginia, USA, ACM (2002) 56-62