A double access control model for web services based information system

被引:0
|
作者
Chen, Xueqin [1 ]
Wu, Huizhong [1 ]
Zhu, Yaoqin [1 ]
机构
[1] Nanjing Univ Sci & Tech, Sch Comp Sci & Tech, Lab 603, Nanjing 210094, Peoples R China
关键词
web services; information system; security; access control; functions and resources;
D O I
10.1109/ICSICT.2008.4734715
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, distributed computing technologies have developed rapidly, such as web services and other XML-based technologies. Information systems enter into a wide-area distributed computing environment. For web services based information systems, the separation between functions and resources enables reusability. However, it is difficult for traditional Access control models to deal with. The security of system encounters with challenges. This paper proposes a double access control model based on attributes to achieve the access control of system functions and resources. The access control decision of functions depends on subject attributes. The decision of resources relies on three attributes': subject attributes, resources attributes and environments attributes. Consistency of access controls between functions and resources is solved by subject's attributes certificate and shared policy. Certificate proxy is utilized to achieve single sign-on, authenticate and authority in wide-area environment. Furthermore, we depict the process flow of the access control in detail. The proposed model is implemented on XACML.NET package and applied in a web services based information system in NET Environment. At last, the performance of resource access control is analyzed and tested by VSTE-ST 2005. The results of practical application and experiment prove the feasibility and usability of the model.
引用
收藏
页码:1045 / 1050
页数:6
相关论文
共 50 条
  • [1] The hybrid model for web services security Access control and information flow control
    Kedjar, Saadia
    Tari, Abdelkamel
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 194 - +
  • [2] An attribute-based access control model for Web services
    Shen Hai-bo
    Hong Fan
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2006, : 74 - +
  • [3] An attribute and role based access control model for web services
    Liu, M
    Guo, HQ
    Su, JD
    [J]. PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 1302 - 1306
  • [4] Role-based access control system for web services
    Feng, X
    Guoyuan, L
    Hao, H
    Li, X
    [J]. FOURTH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY, PROCEEDINGS, 2004, : 357 - 362
  • [5] A metadata-based access control model for web services
    Yague, MI
    Maña, A
    Lopez, J
    [J]. INTERNET RESEARCH, 2005, 15 (01) : 99 - 116
  • [6] Access control model for web services based on attribute certificate
    Jin, Li'na
    Jiang, Xinghao
    Li, Jianhua
    [J]. Jisuanji Gongcheng/Computer Engineering, 2006, 32 (16): : 136 - 138
  • [7] Access Control and Information Flow Control for Web Services Security
    Kedjar, Saadia
    Tari, Abdelkamel
    Bertok, Peter
    [J]. INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2016, 11 (01) : 44 - 76
  • [8] A flexible access control model for Web services
    Bertino, E
    Squicciarini, AC
    [J]. FLEXIBLE QUERY ANSWERING SYSTEMS, PROCEEDINGS, 2004, 3055 : 13 - 16
  • [9] Access Control Model for Composite Web Services
    Jiang, Huangqin
    Zhang, Hongqi
    [J]. PROCEEDINGS OF 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY, 2012, : 684 - 688
  • [10] An adaptive access control model for Web services
    Bertino, Elisa
    Squicciarini, Anna C.
    Martino, Lorenzo
    Paci, Federica
    [J]. INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2006, 3 (03) : 27 - 60