Protecting Consumer Data in Composite Web Services

Craig Pearce

School of Computer Science and IT

Date and time: 11.30am-12.30pm, Friday 6th May, 2005

Venue: 10.08.04

Chair: Xiaodong Li

Abstract:

The increasing number of linkable vendor-operated databases present unique threats to customer privacy and security intrusions, as personal information communicated in online transactions can be misused by the vendor. To date, research has focused on digital privacy policies negotiated between customer and vendor, with the vendor stating which personal information is collected and the purpose for collection.

However, existing methods fail in the event of a vendor operating against their stated privacy policy, leading to loss of customer privacy and security due to trusted customer information being placed in control of an untrusted vendor. Anonymity may not be applicable when transactions require identification of participants.

We propose a service-oriented technically enforceable system that preserves privacy and security for customers transacting with untrusted online vendors. The system extends to support protection of customer privacy when multiple vendors interact in composite web services. A semi-trusted processor is introduced for safe execution of sensitive customer information in a protected environment and provides accountability in case of disputed transactions.

About the speaker:

Craig Pearce is currently a PhD student at the School of Computer Science and IT, RMIT University. He is under the supervision of Dr. Peter Bertok and Dr. Ron Van Schyndel.


Seminar Organisation

Seminars are free and open to the general public. No booking is necessary. If you are interested in giving a presentation in this seminar series, or to make suggestions for speakers, please contact Xiaodong Li, the seminar co-ordinator.