Policies for Web Security Services

Policies for Web Security Services

Konstantina Stoupa (Aristotle University of Thessaloniki, Greece) and Athena Vakali (Aristotle University of Thessaloniki, Greece)
Copyright: © 2006 |Pages: 21
DOI: 10.4018/978-1-59140-588-7.ch003
OnDemand PDF Download:
List Price: $37.50
10% Discount:-$3.75


This chapter analyzes the various types of policies implemented by the Web security services. According to X.800 definition, there are five basic Web security services categories: authentication, non-repudiation, access control, data integrity, and data confidentiality. In this chapter, we discuss access control and data privacy services. Access control services may adopt various models according to the needs of the protected environment. In order to guide the design of access control models, several policy-expressing languages have been standardized. Our contribution is to describe and compare the various models and languages. Data privacy policies are categorized according to their purpose, that is, whether they express promises and preferences, manage the dissemination of privacy preferences, or handle the fulfillment of the privacy promises. The chapter is enriched with a discussion on the future trends in access control and data privacy.

Complete Chapter List

Search this Book: