dc.contributor.advisor |
Ye, X |
en |
dc.contributor.author |
Zhong, Lei |
en |
dc.date.accessioned |
2011-02-28T02:20:39Z |
en |
dc.date.issued |
2011 |
en |
dc.identifier.uri |
http://hdl.handle.net/2292/6514 |
en |
dc.description |
Full text is available to authenticated members of The University of Auckland only. |
en |
dc.description.abstract |
Due to the rapid development of web service based service-oriented architecture (SOA), more and more users are using the services provided by third party service providers. Many users collaborate with each other to carry out complex tasks by invoking the operations of the service providers and by sharing the data stored on the service providers. Traditionally, each service provider specifies an access control policy to control the access to the data stored on the service provider. As a service provider might host data belonging to many users and different users might have different access control policies for their data, maintaining a single access control policy for all users' data become difficult and inflexible. Enforcing the access control policy requires the programmers' careful consideration when implementing the system. The oversights of the programmers might leave security holes in the system. This thesis proposed a User-Centric Data-level Access Control Scheme in which the access control policy of a data item is stored together with the data item. The scheme allows the owners of data to specify the access policies for the data. That is, instead of having a single access control policy for all the data in the system, each data item is given its own access control policy. The scheme also provides a program transformer that can be used by the service providers to insert code at relevant places in the source program for carrying out access control and for tracking the data flow amongst the statements in the system. Compared with other existing schemes, the proposed scheme is more flexible in managing data protection and relieves the programmer from manually enforcing access control and data flow control in their applications. A prototype of the scheme has been implemented and the overhead of the system has been measured. |
en |
dc.publisher |
ResearchSpace@Auckland |
en |
dc.relation.ispartof |
Masters Thesis - University of Auckland |
en |
dc.relation.isreferencedby |
UoA99220287414002091 |
en |
dc.rights |
Restricted Item. Available to authenticated members of The University of Auckland. |
en |
dc.rights.uri |
https://researchspace.auckland.ac.nz/docs/uoa-docs/rights.htm |
en |
dc.title |
Protecting Data on Service Providers |
en |
dc.type |
Thesis |
en |
thesis.degree.discipline |
Computer Science |
en |
thesis.degree.grantor |
The University of Auckland |
en |
thesis.degree.level |
Masters |
en |
dc.rights.holder |
Copyright: the author |
en |
pubs.elements-id |
206644 |
en |
pubs.record-created-at-source-date |
2011-02-28 |
en |
dc.identifier.wikidata |
Q112888515 |
|