Unlike traditional monolithic approaches to web-service composition, modern web services are built by integrating various external sub-services, such as OpenID authentication, cloud-based IaaS for compute and storage, payment gateways, and more. Additionally, application-specific sub-services, like JavaScript libraries and web-analytics, are often incorporated-particularly in e-commerce platforms. This modern modular approach offers clear advantages, including faster deployment, enhanced user convenience, and lower service delivery costs. However, it also raises significant privacy concerns, as users’ interactions with these services are exposed to third-party sub-services, allowing for observation and inference. In the early days of online banking, David Chaum proposed eCash, a system that allowed banks to authenticate payments without monitoring their customers’ transaction details. Beyond payments, however, the issue of linking users to their online actions—by both the primary service provider and its associated sub-services—has made it difficult to identify and prevent privacy violations. Schneier and Raghavan introduced strategies to enhance privacy in online services through the decoupling principle, which focuses on separating user actions from their identity to prevent linkability. The foundation of privacy breaches in online transactions is the ability to observe and connect an authenticated user’s identity with their actions. SPKI (Simple Public Key Infrastructure) offers a way to define, use, and manage identity and authorizations independently. In this paper, we propose an SPKI-based framework that can be integrated into online transaction processes to decouple identity from actions. Through illustrative examples, we demonstrate the framework’s utility and argue that it provides greater expressiveness and flexibility compared to existing privacy frameworks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Decoupling Mechanism for Transaction Privacy

  • Vishwas Patil,
  • R. K. Shyamasundar

摘要

Unlike traditional monolithic approaches to web-service composition, modern web services are built by integrating various external sub-services, such as OpenID authentication, cloud-based IaaS for compute and storage, payment gateways, and more. Additionally, application-specific sub-services, like JavaScript libraries and web-analytics, are often incorporated-particularly in e-commerce platforms. This modern modular approach offers clear advantages, including faster deployment, enhanced user convenience, and lower service delivery costs. However, it also raises significant privacy concerns, as users’ interactions with these services are exposed to third-party sub-services, allowing for observation and inference. In the early days of online banking, David Chaum proposed eCash, a system that allowed banks to authenticate payments without monitoring their customers’ transaction details. Beyond payments, however, the issue of linking users to their online actions—by both the primary service provider and its associated sub-services—has made it difficult to identify and prevent privacy violations. Schneier and Raghavan introduced strategies to enhance privacy in online services through the decoupling principle, which focuses on separating user actions from their identity to prevent linkability. The foundation of privacy breaches in online transactions is the ability to observe and connect an authenticated user’s identity with their actions. SPKI (Simple Public Key Infrastructure) offers a way to define, use, and manage identity and authorizations independently. In this paper, we propose an SPKI-based framework that can be integrated into online transaction processes to decouple identity from actions. Through illustrative examples, we demonstrate the framework’s utility and argue that it provides greater expressiveness and flexibility compared to existing privacy frameworks.