Huang ZhiQiu
Alma Mater:南京航空航天大学
Education Level:南京航空航天大学
Degree:Doctoral Degree in Engineering
School/Department:College of Computer Science and Technology
Discipline:Cyberspace Security. Computer Science and Technology. Software Engineering
Contact Information:025-84892400
Affiliation of Author(s):计算机科学与技术学院/人工智能学院/软件学院
Journal:Ruan Jian Xue Bao
Abstract:Many service composition scenarios involve the sharing of user's privacy data. Due to the transparency of composition's business logic and lack of privacy protocol between user and member service, how to prevent the leakage of user privacy information has become a hot research topic in the field of service-oriented computing. A static analysis method of secure privacy information flow for service composition is proposed in this article according to the characteristics of privacy protection. Firstly, a security model is developed to formalize the security policy of privacy information flow on three aspects: service reputation, retention and purpose. Then, the composition is modeled with privacy workflow net, which gives support to the analysis of privacy information flow, and the detection of privacy information leakage is performed by analyzing execution paths of composition. Finally, a case study is included to demonstrate the effectiveness of the proposed method, and the performance experiment is also presented. Compared with the existing relevant works, the security model proposed reflects the characteristics of privacy protection, and the analysis method is able to deal with issues caused by the aggregation of privacy data items. Therefore, the application of this method can prevent the information leakage more efficiently. © Copyright 2018, Institute of Software, the Chinese Academy of Sciences. All rights reserved.
ISSN No.:1000-9825
Translation or Not:no
Date of Publication:2018-01-01
Co-author:Peng, Huan-Feng,Liu, Lin-Yuan,ly,Ke, Chang-Bo
Correspondence Author:Huang ZhiQiu
黄志球,男,博士,教授,博士生导师,国家教育部计算机基础教学(理工类)指导委员会委员,国防科技工业质量专家委员会委员 ,中国计算机学会理事、“系统软件”专业委员会副主任、“软件工程”委员,中国电子学会软件定义推进委员会委员,IEEE计算机学会南京分会副主席,CCF南京主席,江苏省计算机学会常务理事,江苏省软件人才基金会理事,工信部重点实验室“高安全系统的软件开发与验证重点实验室”主任。