Access control in dynamic XML-based web-services with X-RBAC

被引:0
|
作者
Bhatti, R [1 ]
Joshi, JBD [1 ]
Bertino, E [1 ]
Ghafoor, A [1 ]
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
关键词
XML; RBAC; access control; web-services;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy specification for securing Web services is fast emerging as a key research area due to rapid proliferation of Web services in modem day enterprise applications. Whilst the use of XML technology to support these Web services has resulted in their tremendous growth, it has also introduced a new set of security challenges specific to these Web services. Though there has been recent research in areas of XML-based document security, these challenges have not been addressed within the XML framework. In this paper, we present X-RBAC, an XML-based RBAC policy specification framework for enforcing access control in dynamic XML-based Web services. An X-RBAC system has been implemented as a Java application, and is based on a specification language that addresses specific security requirements of these Web services. We discuss the salient features of the specification language, and present the software architecture of our X-RBAC system.
引用
收藏
页码:243 / 249
页数:7
相关论文
共 50 条
  • [1] An XML-based language for access control specifications in an RBAC environment
    Stoupa, KE
    Vakali, AI
    2003 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS, VOLS 1-5, CONFERENCE PROCEEDINGS, 2003, : 1717 - 1722
  • [2] XML-based declarative access control
    Steele, R
    Gardner, W
    Dillon, TS
    Erradi, A
    SOFSEM 2005:THEORY AND PRACTICE OF COMPUTER SCIENCE, 2005, 3381 : 310 - 319
  • [3] ActiveWeb: XML-based active rules for Web view derivations and access control
    Kiyomitsu, H
    Takeuchi, A
    Tanaka, K
    PROCEEDINGS OF THE WORKSHOP ON INFORMATION TECHNOLOGY FOR VIRTUAL ENTERPRISES, ITVE 2001, 2001, 23 (06): : 31 - 39
  • [4] A XML-based quality model for Web services certification
    Dias, J. Jorge
    Cunha, J. Adson O. G. da
    Alvaro, Alexandre
    de Barros, Roberto S. M.
    Meira, Silvio
    ICEIS 2007: PROCEEDINGS OF THE NINTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: DATABASES AND INFORMATION SYSTEMS INTEGRATION, 2007, : 288 - 294
  • [5] XML-Based specification for web services document security
    Bhatti, R
    Bertino, E
    Ghafoor, A
    Joshi, JBD
    COMPUTER, 2004, 37 (04) : 41 - +
  • [6] XML-based web services technology to implement a prototype command and control system
    Lin, Ching-Show
    Liang, Chia-Hao
    DEFENCE SCIENCE JOURNAL, 2006, 56 (04) : 591 - 597
  • [7] XML-based monitoring and operating for Web Services in automation
    Braune, Annerose
    Hennig, Stefan
    Schaft, Torsten
    2007 5TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS, VOLS 1-3, 2007, : 797 - 802
  • [8] Coyote: An XML-based framework for web services testing
    Tsai, WT
    Paul, R
    Song, WW
    Cao, ZB
    7TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH ASSURANCE SYSTEMS ENGINEERING, PROCEEDINGS, 2002, : 173 - 174
  • [9] Web Services: XML-based system integrated techniques
    Yu, SC
    Chen, RS
    ELECTRONIC LIBRARY, 2003, 21 (04): : 358 - 366
  • [10] XML-based distributed access control system
    López, J
    Maña, A
    Yagüe, MI
    E-COMMERCE AND WEB TECHNOLOGIES, PROCEEDINGS, 2002, 2455 : 203 - 213