Trust policy management for the financial industry using semantic web rules

Thesis (S.M.M.O.T.)--Massachusetts Institute of Technology, Sloan School of Management, Management of Technology Program, 2004. === Includes bibliographical references (leaves 89-94). === Trust Management is a growing problem in large corporations today. In industries like financial services, firms...

Full description

Bibliographic Details
Main Author: Neogy, Chitravanu
Other Authors: Benjamin Grosof.
Format: Others
Language:English
Published: Massachusetts Institute of Technology 2005
Subjects:
Online Access:http://hdl.handle.net/1721.1/17811
id ndltd-MIT-oai-dspace.mit.edu-1721.1-17811
record_format oai_dc
spelling ndltd-MIT-oai-dspace.mit.edu-1721.1-178112019-05-02T16:26:21Z Trust policy management for the financial industry using semantic web rules Neogy, Chitravanu Benjamin Grosof. Massachusetts Institute of Technology. Management of Technology Program. Massachusetts Institute of Technology. Management of Technology Program. Management of Technology Program. Thesis (S.M.M.O.T.)--Massachusetts Institute of Technology, Sloan School of Management, Management of Technology Program, 2004. Includes bibliographical references (leaves 89-94). Trust Management is a growing problem in large corporations today. In industries like financial services, firms need to comply with constantly changing regulations, security requirements and business policies. Information technology is often the backbone of the processes that are regulated by such policies. Traditionally fine-grained Trust Management has been attempted by embedding policies within business logic of silo software applications. This practice leads to high total costs of ownership, minimal interoperability, potential security vulnerabilities and low management visibility into policy specifications and enforcement, which complicates compliance challenges with regulations like Sarbanes Oxley. This thesis makes several new contributions. First, it evaluates trust-policy related applications in the overall financial services industry that can benefit from rule technologies. A second contribution is proposing SCLP RuleML, an emerging semantic web rule language, for representing trust policies (SCLP = The Situated Courteous Logic Programs knowledge representation). A third contribution is providing several financial application scenarios in SCLP that demonstrate the effectiveness of RuleML, including credit card authorizations for electronic transactions, Check 21 processing in banks and account access control in brokerage or mutual fund systems. Finally we provide a rationale and a proposal for RuleML to be a reference implementation of extensible Access Control Markup Language (XACML), an evolving OASIS standard for digital authorization. (cont.) Potential benefits of such standardization include lower cost and more effectiveness of policy administration; better governance and coordination through centralized ownership or interoperability; and reduced system development costs over the full life cycle. by Chitravanu Neogy. S.M.M.O.T. 2005-06-02T18:46:00Z 2005-06-02T18:46:00Z 2004 2004 Thesis http://hdl.handle.net/1721.1/17811 56557578 eng M.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission. http://dspace.mit.edu/handle/1721.1/7582 94 leaves 4721928 bytes 4730914 bytes application/pdf application/pdf application/pdf Massachusetts Institute of Technology
collection NDLTD
language English
format Others
sources NDLTD
topic Management of Technology Program.
spellingShingle Management of Technology Program.
Neogy, Chitravanu
Trust policy management for the financial industry using semantic web rules
description Thesis (S.M.M.O.T.)--Massachusetts Institute of Technology, Sloan School of Management, Management of Technology Program, 2004. === Includes bibliographical references (leaves 89-94). === Trust Management is a growing problem in large corporations today. In industries like financial services, firms need to comply with constantly changing regulations, security requirements and business policies. Information technology is often the backbone of the processes that are regulated by such policies. Traditionally fine-grained Trust Management has been attempted by embedding policies within business logic of silo software applications. This practice leads to high total costs of ownership, minimal interoperability, potential security vulnerabilities and low management visibility into policy specifications and enforcement, which complicates compliance challenges with regulations like Sarbanes Oxley. This thesis makes several new contributions. First, it evaluates trust-policy related applications in the overall financial services industry that can benefit from rule technologies. A second contribution is proposing SCLP RuleML, an emerging semantic web rule language, for representing trust policies (SCLP = The Situated Courteous Logic Programs knowledge representation). A third contribution is providing several financial application scenarios in SCLP that demonstrate the effectiveness of RuleML, including credit card authorizations for electronic transactions, Check 21 processing in banks and account access control in brokerage or mutual fund systems. Finally we provide a rationale and a proposal for RuleML to be a reference implementation of extensible Access Control Markup Language (XACML), an evolving OASIS standard for digital authorization. === (cont.) Potential benefits of such standardization include lower cost and more effectiveness of policy administration; better governance and coordination through centralized ownership or interoperability; and reduced system development costs over the full life cycle. === by Chitravanu Neogy. === S.M.M.O.T.
author2 Benjamin Grosof.
author_facet Benjamin Grosof.
Neogy, Chitravanu
author Neogy, Chitravanu
author_sort Neogy, Chitravanu
title Trust policy management for the financial industry using semantic web rules
title_short Trust policy management for the financial industry using semantic web rules
title_full Trust policy management for the financial industry using semantic web rules
title_fullStr Trust policy management for the financial industry using semantic web rules
title_full_unstemmed Trust policy management for the financial industry using semantic web rules
title_sort trust policy management for the financial industry using semantic web rules
publisher Massachusetts Institute of Technology
publishDate 2005
url http://hdl.handle.net/1721.1/17811
work_keys_str_mv AT neogychitravanu trustpolicymanagementforthefinancialindustryusingsemanticwebrules
_version_ 1719040276408827904