首页> 外文学位 >Cross-Domain Data Dissemination and Policy Enforcement.
【24h】

Cross-Domain Data Dissemination and Policy Enforcement.

机译:跨域数据分发和策略执行。

获取原文
获取原文并翻译 | 示例

摘要

Modern information systems are distributed and highly dynamic. They comprise a number of hosts from heterogeneous domains, which collaborate, interact, and share data to handle client requests. Examples include cloud-hosted solutions, service-oriented architectures, electronic healthcare systems, product lifecycle management systems, and so on. A client request translates into multiple internal interactions involving different parties; each party can access and further share the client's data. However, such interactions may share data with unauthorized parties and violate the client's disclosure policies. In this case, the client has no knowledge of or control over interactions beyond its trust domain; therefore, the client has no means of detecting violations. Opaque data sharing in such distributed systems introduces new security challenges not present in the traditional systems. Existing solutions provide point-to-point secure data transmission and ensure security within a single domain, but are insufficient for distributed data dissemination because of the involvement of multiple cross-domain parties.;This dissertation addresses the problem of policy-based distributed data dissemination (PD3) and proposes a data-centric solution for end-to-end secure data disclosure in distributed interactions. The solution ensures that the data are distributed along with the policies that dictate data access and an execution monitor (a policy evaluation and enforcement mechanism) that controls data disclosure and protects data dissemination throughout the interaction lifecycle. It empowers data owners with control of data disclosure decisions outside their trust domains and reduces the risk of unauthorized access.;This dissertation makes the following contributions. First, it presents a formal description of the PD3 problem and identifies the main requirements for a new solution. Second, it introduces EPICS, an extensible framework for enforcing policies in composite Web services, and describes its design, implementation, and evaluation. Third, it demonstrates a novel application of the proposed solution to address privacy and identity management in cloud computing.
机译:现代信息系统是分布式的,并且高度动态。它们包含许多来自异构域的主机,这些主机协作,交互和共享数据以处理客户端请求。示例包括云托管的解决方案,面向服务的体系结构,电子医疗系统,产品生命周期管理系统等。客户请求转换为涉及不同方的多个内部交互;各方都可以访问并进一步共享客户的数据。但是,此类交互可能会与未经授权的各方共享数据,并且违反了客户的披露政策。在这种情况下,客户不了解或控制超出其信任域的交互;因此,客户端无法检测违规。这种分布式系统中不透明的数据共享带来了传统系统中不存在的新安全挑战。现有的解决方案提供了点对点的安全数据传输并确保了单个域内的安全性,但是由于涉及多个跨域方的参与,因此不足以进行分布式数据分发。;本论文解决了基于策略的分布式数据分发问题(PD3),并提出了一种以数据为中心的解决方案,用于分布式交互中的端到端安全数据公开。该解决方案确保数据与指示数据访问的策略一起分发,并确保在整个交互生命周期中控制数据公开并保护数据分发的执行监视器(策略评估和实施机制)。它使数据所有者能够控制其信任域之外的数据公开决策,并减少了未经授权的访问的风险。首先,它给出了PD3问题的形式描述,并确定了新解决方案的主要要求。其次,它介绍了EPICS,EPICS是用于在复合Web服务中执行策略的可扩展框架,并描述了其设计,实现和评估。第三,它演示了该解决方案在云计算中解决隐私和身份管理的新颖应用。

著录项

  • 作者

    Ranchal, Rohit.;

  • 作者单位

    Purdue University.;

  • 授予单位 Purdue University.;
  • 学科 Computer science.;Computer engineering.;Information technology.
  • 学位 Ph.D.
  • 年度 2015
  • 页码 109 p.
  • 总页数 109
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号