XML-Based specification for web services document security

被引:37
|
作者
Bhatti, R [1 ]
Bertino, E
Ghafoor, A
Joshi, JBD
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Univ Pittsburgh, Dept Informat Sci & Telecommun, Pittsburgh, PA 15260 USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/MC.2004.1297300
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet and related technologies have seen tremendous growth in distributed applications such as medicine, education, e-commerce, and digital libraries. As demand increases for online content and integrated, automated services, various applications employ Web services technology for document exchange among data repositories. Web services provide a mechanism to expose data and functionality using standard protocols, and hence to integrate many features that enhance Web applications. XML, a well-established text format, is playing an increasingly important role in supporting Web services. XML separates data from style and format definition and allows uniform representation, interchange, sharing, and dissemination of information content over the Internet.(1,2) It is thus a natural contender as a standard for marking up the data that distributed Web-based applications exchange. This interoperability paradigm lets businesses dynamically publish, discover, and aggregate a range of Web services through the Internet to more easily create innovative business processes and value chains.(3) This advantage, however, is accompanied by security concerns related to disseminating secure documents. Security has become a primary concern for all enterprises exposing sensitive data and business ss processes as Web services. XML and Web services provide a simplified application integration framework that drives demand for models that support secure information interchange. Examples of secure Web services that require stricter access controls include searching digital library contents based on user privileges, retrieving results from a medical center's patient database based on user status, and exchanging sensitive financial data between institutions based on user membership levels. Providing document security in XML-based Web services requires access control models that offer specific capabilities. Our XML-based access control specification language addresses a new set of challenges that traditional security models do not address.
引用
收藏
页码:41 / +
页数:10
相关论文
共 50 条
  • [41] Groundwork for True XML-based Security Pattern Languages
    TAWFIQ S.M.Barhoom
    张申生
    Journal of DongHua University, 2005, (01) : 120 - 123
  • [42] XML-Based Web Data Pattern Discovery and Extraction
    Jia, Rui
    Xu, Shicheng
    Peng, Chengbao
    INFORMATION COMPUTING AND APPLICATIONS, PT 1, 2012, 307 : 708 - 715
  • [43] XGuide -: A practical guide to XML-based Web engineering
    Kerer, C
    Kirda, E
    Krügel, C
    WEB ENGINEERING AND PEER TO PEER COMPUTING, 2002, 2376 : 104 - 117
  • [44] XML-based approach for fast prototyping of Web applications
    Navarro, A
    Fernandez-Manjon, B
    Fernandez-Valmayor, A
    Sierra, JL
    WEB ENGINEERING, PROCEEDINGS, 2003, 2722 : 241 - 244
  • [45] An XML-based wrapper generator for Web information extraction
    Liu, L
    Han, W
    Buttler, D
    Pu, C
    Tang, W
    SIGMOD RECORD, VOL 28, NO 2 - JUNE 1999: SIGMOD99: PROCEEDINGS OF THE 1999 ACM SIGMOD - INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 1999, : 540 - 543
  • [46] An XML-based multimedia document processing model for content adaptation
    Villard, L
    Roisin, C
    Layaïda, N
    DIGITAL DOCUMENTS: SYSTEMS AND PRINCIPLES, 2004, 2023 : 104 - 119
  • [47] Temporal queries and version management in XML-based document archives
    Wang, Fusheng
    Zaniolo, Carlo
    DATA & KNOWLEDGE ENGINEERING, 2008, 65 (02) : 304 - 324
  • [48] XML-based IS09000 electronic document management system
    Yao, YH
    Trappey, AJC
    Ho, PS
    ROBOTICS AND COMPUTER-INTEGRATED MANUFACTURING, 2003, 19 (04) : 355 - 370
  • [49] An XML-based agent model for supporting user activities on the Web
    DIMET Università Mediterranea di Reggio Calabria, Via Graziella, Localita Feo di Vito, 89060 Reggio Calabria, Italy
    不详
    Web Intell. Agent Syst., 2006, 2 (181-207):
  • [50] XML-based Web Information Extraction System Design and Implementation
    Jun, Ma
    Li Tihong
    PROCEEDINGS OF 2010 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY (ICCSIT 2010), VOL 8, 2010, : 551 - 554