Service-based computing meets privacy

Relatore:  Dott.ssa Federica Paci - Università di Trento
  giovedì 20 marzo 2014 alle ore 16.30
Service-oriented architectures and cloud computing make available on the Internet a large pool of services among which service consumers can select and invoke the services that best meet their needs.
However, service selection and invocation involve the exchange of a large amount of sensitive and personal data between service consumers and service providers, which raises consumers’ and service providers’ privacy concerns. Service consumers are concerned about disclosing sensitive and personal information to service providers because they feel they do not retain any control over their data once these has been collected. Similarly, service providers are concerned about disclosing the information necessary to invoke a service - e.g service descriptions, access control policies, WS-Policy specification - to service consumers because they contain sensitive information about the organization or the service itself that can be exploited to launch attacks: e.g fingerprint the service or infer service vulnerabilities.

My research focuses on devising approaches to minimize the risk of privacy breaches for service consumers and service providers. In this talk, I will first discuss the main privacy concerns that service consumers and service providers have with respect to service selection and invocation. Then, I will introduce two approaches that alleviate service consumers and service providers privacy concerns by limiting the disclosure of personal and sensitive information. The first approach that I will introduce helps service consumers to select and compose services that minimize the risk of unauthorized disclosure of their personal information.The approach ranks admissible composite services (i.e., composite services whose privacy policy satisfy user preferences) with respect to the risk of misuse of personal data. Then, I will present an approach that allows service providers to limit during service invocation the knowledge that service consumers have of the access control policies they are subject to, while providing service consumers some guarantee that they will complete the interaction with the service.  I will conclude the talk by discussing new risks posed to services consumers’ privacy by the use of big data analytics and outlining a possible solution. 

Titolo Formato  (Lingua, Dimensione, Data pubblicazione)
Biografia Relatrice  pdfpdf (it, 39 KB, 12/03/14)

Referente
Roberto Giacobazzi

Referente esterno
Data pubblicazione
12 marzo 2014

Offerta formativa

Condividi