XML-Based specification for web services document security

被引:37
|
作者
Bhatti, R [1 ]
Bertino, E
Ghafoor, A
Joshi, JBD
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Univ Pittsburgh, Dept Informat Sci & Telecommun, Pittsburgh, PA 15260 USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/MC.2004.1297300
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet and related technologies have seen tremendous growth in distributed applications such as medicine, education, e-commerce, and digital libraries. As demand increases for online content and integrated, automated services, various applications employ Web services technology for document exchange among data repositories. Web services provide a mechanism to expose data and functionality using standard protocols, and hence to integrate many features that enhance Web applications. XML, a well-established text format, is playing an increasingly important role in supporting Web services. XML separates data from style and format definition and allows uniform representation, interchange, sharing, and dissemination of information content over the Internet.(1,2) It is thus a natural contender as a standard for marking up the data that distributed Web-based applications exchange. This interoperability paradigm lets businesses dynamically publish, discover, and aggregate a range of Web services through the Internet to more easily create innovative business processes and value chains.(3) This advantage, however, is accompanied by security concerns related to disseminating secure documents. Security has become a primary concern for all enterprises exposing sensitive data and business ss processes as Web services. XML and Web services provide a simplified application integration framework that drives demand for models that support secure information interchange. Examples of secure Web services that require stricter access controls include searching digital library contents based on user privileges, retrieving results from a medical center's patient database based on user status, and exchanging sensitive financial data between institutions based on user membership levels. Providing document security in XML-based Web services requires access control models that offer specific capabilities. Our XML-based access control specification language addresses a new set of challenges that traditional security models do not address.
引用
收藏
页码:41 / +
页数:10
相关论文
共 50 条
  • [31] Research of XML-Based Web Report System
    Liang, Kun
    Li, Yujun
    Duan, Jinghong
    Wang, Yiming
    2017 IEEE 3RD INTERNATIONAL CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY, IEEE 3RD INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) AND 2ND IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2017, : 96 - 100
  • [32] Research and Realization of Web Services Security Based on XML Signature
    Gu Yue-sheng
    Zhang Bao-jian
    Xu Wu
    2009 INTERNATIONAL CONFERENCE ON NETWORKING AND DIGITAL SOCIETY, VOL 2, PROCEEDINGS, 2009, : 116 - 118
  • [33] Access control in dynamic XML-based web-services with X-RBAC
    Bhatti, R
    Joshi, JBD
    Bertino, E
    Ghafoor, A
    ICWS'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON WEB SERVICES, 2003, : 243 - 249
  • [34] XML-based document model for networked manufacturing system
    Yu, Qing-Mei
    Yin, Chao-Wan
    Liu, Zhi-Gang
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2003, 9 (07): : 601 - 607
  • [35] An XML-Based protocol for distributed event services
    Smith, W
    Gunter, D
    Quesnel, D
    PDPTA'2001: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, 2001, : 1668 - 1674
  • [36] XFlow: An XML-based document-centric workflow
    Marchetti, A
    Tesconi, M
    Minutoli, S
    WEB INFORMATION SYSTEMS ENGINEERING - WISE 2005, 2005, 3806 : 290 - 303
  • [37] XML-based Specification of the Project Management Domain and Its Application
    Berzisa, Solvita
    DATABASES AND INFORMATION SYSTEMS VI: SELECTED PAPERS FROM THE NINTH INTERNATIONAL BALTIC CONFERENCE (DB&IS 2010), 2011, 224 : 213 - 226
  • [38] Development of an XML-based specification for traffic model data exchange
    Courage, KG
    Washburn, SS
    Kim, JT
    TRANSPORTATION DATA AND INFORMATION TECHNOLOGY RESEARCH: PLANNING AND ADMINISTRATION, 2002, (1804): : 144 - 150
  • [39] Security and Performance of Mobile XML Web Services
    Nguyen, Thao Thanh
    Jorstad, Ivar
    van Thanh, Do
    FOURTH INTERNATIONAL CONFERENCE ON NETWORKING AND SERVICES (ICNS 2008), PROCEEDINGS, 2008, : 261 - 265
  • [40] An XML-based quality of service enabling language for the Web
    Gu, XH
    Nahrstedt, K
    Yuan, WH
    Wichadakul, D
    Xu, DY
    JOURNAL OF VISUAL LANGUAGES AND COMPUTING, 2002, 13 (01): : 61 - 95