{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T17:53:10Z","timestamp":1754157190395,"version":"3.41.2"},"reference-count":24,"publisher":"Emerald","issue":"2","license":[{"start":{"date-parts":[[2009,4,3]],"date-time":"2009-04-03T00:00:00Z","timestamp":1238716800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009,4,3]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>This paper aims to describe a bilateral symmetric approach to authorization, privacy protection and obligation enforcement in distributed transactions. The authors introduce the concept of the obligation of trust (OoT) protocol as a privacy assurance and authorization mechanism that is built upon the XACML standard. The OoT allows two communicating parties to dynamically exchange their privacy and authorization requirements and capabilities, which the authors term a notification of obligation (NoB), as well as their commitments to fulfilling each other's requirements, which the authors term signed acceptance of obligations (SAO). The authors seek to describe some applicability of these concepts and to show how they can be integrated into distributed authorization systems for stricter privacy and confidentiality control.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>Existing access control and privacy protection systems are typically unilateral and provider\u2010centric, in that the enterprise service provider assigns the access rights, makes the access control decisions, and determines the privacy policy. There is no negotiation between the client and the service provider about which access control or privacy policy to use. The authors adopt a symmetric, more user\u2010centric approach to privacy protection and authorization, which treats the client and service provider as peers, in which both can stipulate their requirements and capabilities, and hence negotiate terms which are equally acceptable to both parties.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>The authors demonstrate how the obligation of trust protocol can be used in a number of different scenarios to improve upon the mechanisms that are currently available today.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>This approach will serve to increase trust in distributed transactions since each communicating party receives a difficult to repudiate digitally signed acceptance of obligations, in a standard language (XACML), which can be automatically enforced by their respective computing machinery.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The paper adds to current research in trust negotiation, privacy protection and authorization by combining all three together into one set of standardized protocols. Furthermore, by providing hard to repudiate signed acceptance of obligations messages, this strengthens the legal case of the injured party should a dispute arise.<\/jats:p><\/jats:sec>","DOI":"10.1108\/10662240910952328","type":"journal-article","created":{"date-parts":[[2009,4,27]],"date-time":"2009-04-27T05:48:15Z","timestamp":1240811295000},"page":"153-173","source":"Crossref","is-referenced-by-count":7,"title":["Obligations of trust for privacy and confidentiality in distributed transactions"],"prefix":"10.1108","volume":"19","author":[{"given":"U.M.","family":"Mbanaso","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"G.S.","family":"Cooper","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Chadwick","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anne","family":"Anderson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022021019510712500_b1","unstructured":"Anderson, A. (2007), \u201cWeb services profile of XACML (WS\u2010XACML) version 1.0\u201d, working draft 10, OASIS XACML Technical Committee, 10 August, available at: www.oasis\u2010open.org\/committees\/download.php\/24950\/xacml\u20103.0\u2010profile\u2010webservices\u2010v1\u2010wd\u201010.zip (accessed 24 October 2008)."},{"key":"key2022021019510712500_b2","doi-asserted-by":"crossref","unstructured":"Bertino, E.F.E. and Squicciarini, A. (2003), \u201cX\u2010TNL: an XML\u2010based language for trust negotiations\u201d, Fourth IEEE International Workshop on Policies for Distributed Systems and Networks, Lake Como, Italy, June, pp. 81\u20104.","DOI":"10.1109\/POLICY.2003.1206960"},{"key":"key2022021019510712500_b3","doi-asserted-by":"crossref","unstructured":"Bertino, E., Ferrari, E. and Squicciarini, A. (2004), \u201cTrust negotiations: concepts, systems and languages\u201d, Computing in Science and Engineering, Vol. 6 No. 4, pp. 27\u201034.","DOI":"10.1109\/MCSE.2004.22"},{"key":"key2022021019510712500_b4","unstructured":"CA\/Browser Forum (2008), \u201cGuidelines for the issuance and management of extended validation certificates\u201d, available at: www.cabforum.org\/documents.html (accessed 22 October 2008)."},{"key":"key2022021019510712500_b5","unstructured":"Liberty Alliance Project (2006), \u201cLiberty ID\u2010WSF web services framework overview version: 2.0\u201d, available at: www.projectliberty.org\/liberty\/specifications__1 (accessed 24 October 2008)."},{"key":"key2022021019510712500_b6","doi-asserted-by":"crossref","unstructured":"Mbanaso, U., Cooper, G.S., Chadwick, D.W. and Proctor, S. (2006), \u201cPrivacy preserving trust authorization using XACML\u201d, Proc. 2nd International Workshop on Trust, Security and Privacy for Ubiquitous Computing (TSPUC 2006), Niagara\u2010Falls, Buffalo\u2010NY, June, pp. 673\u20108.","DOI":"10.1109\/WOWMOM.2006.92"},{"key":"key2022021019510712500_b7","unstructured":"Morgan, R.L., Cantor, S., Carmody, S., Hoehn, W. and Klingenstein, K. (2004), \u201cFederated security: the shibboleth approach\u201d, Educause Quarterly, Vol. 27 No. 4, available at: http:\/\/connect.educause.edu\/Library\/EDUCAUSE+Quarterly\/FederatedSecurityTheShibb\/39889 (accessed 24 October 2008)."},{"key":"key2022021019510712500_b8","unstructured":"OASIS (2005a), Security Assertion Markup Language (SAML) V2.0, March, available at: http:\/\/saml.xml.org\/saml\u2010specifications (accessed 24 October 2008)."},{"key":"key2022021019510712500_b9","unstructured":"OASIS (2005b), eXtensible Access Control Markup Language (XACML) Version 2.0, February, available at: www.oasis\u2010open.org\/committees\/tc_home.php?wg_abbrev=xacml#technical (accessed 24 October 2008)."},{"key":"key2022021019510712500_b10","unstructured":"OASIS (2006), \u201cWeb services security: SOAP message security 1.1 (WS\u2010Security 2004)\u201d, OASIS standard specification, available at: www.oasis\u2010open.org\/committees\/download.php\/16790\/wss\u2010v1.1\u2010spec\u2010os\u2010SOAPMessageSecurity.pdf (accessed 24 October 2008)."},{"key":"key2022021019510712500_b11","unstructured":"OASIS (2007), \u201cWS\u2010Trust 1.3, OASIS standard\u201d, available at: http:\/\/docs.oasis\u2010open.org\/ws\u2010sx\/ws\u2010trust\/v1.3\/ws\u2010trust.html (accessed 24 October 2008)."},{"key":"key2022021019510712500_b12","unstructured":"OECD (2000), \u201cFair information practices in the electronic marketplace: a report to congress\u201d, May."},{"key":"key2022021019510712500_b13","unstructured":"Pau, L.\u2010F. (2006), \u201cPrivacy negotiation and implications on implementations\u201d, Proc. W3C Workshop on Languages for Privacy Policy Negotiation and Semantics\u2010driven Enforcement, available at: www.w3.org\/2006\/07\/privacy\u2010ws\/papers\/ (accessed 24 October 2008)."},{"key":"key2022021019510712500_b14","unstructured":"Preibusch, S. (2006), \u201cPrivacy negotiations with P3P\u201d, Proc. W3C Workshop on Languages for Privacy Policy Negotiation and Semantics\u2010Driven enforcement, available at: www.w3.org\/2006\/07\/privacy\u2010ws\/papers\/ (accessed 24 October 2008)."},{"key":"key2022021019510712500_b16","unstructured":"Seamons, K.E., Ryutov, T., Zhou, L., Neuman, C. and Leithead, T. (2005), \u201cAdaptive trust negotiation and access control\u201d, Proc. 10th ACM Symposium on Access Control Models and Technologies, Stockholm, Sweden, pp. 139\u201046."},{"key":"key2022021019510712500_b15","doi-asserted-by":"crossref","unstructured":"Seamons, K.E., Winslett, M., Yu, T., Yu, L. and Jarvis, R. (2003), \u201cProtecting privacy during on\u2010line trust negotiation\u201d, LNCS Privacy Enhancing Technologies, Vol. 2482\/\u20101, Springer, Berlin, Heidelberg, pp. 249\u201053.","DOI":"10.1007\/3-540-36467-6_10"},{"key":"key2022021019510712500_b17","doi-asserted-by":"crossref","unstructured":"Skogsrud, H., Benatallah, B. and Casati, F. (2004), \u201cA trust negotiation system for digital library web services\u201d, International Journal on Digital Libraries, Vol. 4 No. 3, pp. 185\u2010207.","DOI":"10.1007\/s00799-004-0083-y"},{"key":"key2022021019510712500_b18","doi-asserted-by":"crossref","unstructured":"Spantzel, A.B., Squicciarini, A.C. and Bertino, E. (2007), \u201cTrust negotiation in identity management\u201d, IEEE Security and Privacy, Vol. 5 No. 2, pp. 55\u201063.","DOI":"10.1109\/MSP.2007.46"},{"key":"key2022021019510712500_b19","unstructured":"University of Salford (2006), \u201cSchema for obligation of trust (OoT)\u201d, available at: http:\/\/infosec.salford.ac.uk\/names\/oot\/ootSchema\/ (accessed 22 October 2008)."},{"key":"key2022021019510712500_b20","unstructured":"W3C (2002a), \u201cA P3P preference exchange language 1.0 (APPEL1.0)\u201d, available at: www.w3.org\/TR\/P3P\u2010preferences\/ (accessed 24 October 2008)."},{"key":"key2022021019510712500_b21","unstructured":"W3C (2002b), \u201cThe platform for privacy preferences 1.0 (P3P1.0) specification\u201d, available at: www.w3.org\/TR\/P3P\/ (accessed 24 October 2008)."},{"key":"key2022021019510712500_b22","unstructured":"W3C (2007), \u201cWeb services policy 1.5 \u2013 Framework (WS\u2010Policy)\u201d, available at: www.w3.org\/TR\/ws\u2010policy\/ (accessed 24 October 2008)."},{"key":"key2022021019510712500_b23","unstructured":"Winsborough, W.H. and Li, N. (2002), \u201cTowards practical automated trust negotiation\u201d, 3rd IEEE International Workshop on Policies for Distributed Systems and Networks, Monterey, CA, June, pp. 92\u2010103."},{"key":"key2022021019510712500_b24","doi-asserted-by":"crossref","unstructured":"Winsborough, W.H. and Ninghui, L. (2002), \u201cProtecting sensitive attributes in automated trust negotiation\u201d, Proc. 2002 ACM Workshop on Privacy in the Electronic Society, Washington DC, November, pp. 41\u201051.","DOI":"10.1145\/644527.644532"}],"container-title":["Internet Research"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/10662240910952328","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240910952328\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240910952328\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T23:40:21Z","timestamp":1753400421000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/intr\/article\/19\/2\/153-173\/182402"}},"subtitle":[],"editor":[{"given":"Jong","family":"Hyuk Park","sequence":"first","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2009,4,3]]},"references-count":24,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2009,4,3]]}},"alternative-id":["10.1108\/10662240910952328"],"URL":"https:\/\/doi.org\/10.1108\/10662240910952328","relation":{},"ISSN":["1066-2243"],"issn-type":[{"type":"print","value":"1066-2243"}],"subject":[],"published":{"date-parts":[[2009,4,3]]}}}