Access control in dynamic XML-based web-services with X-RBAC

被引:0
|
作者
Bhatti, R [1 ]
Joshi, JBD [1 ]
Bertino, E [1 ]
Ghafoor, A [1 ]
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
关键词
XML; RBAC; access control; web-services;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy specification for securing Web services is fast emerging as a key research area due to rapid proliferation of Web services in modem day enterprise applications. Whilst the use of XML technology to support these Web services has resulted in their tremendous growth, it has also introduced a new set of security challenges specific to these Web services. Though there has been recent research in areas of XML-based document security, these challenges have not been addressed within the XML framework. In this paper, we present X-RBAC, an XML-based RBAC policy specification framework for enforcing access control in dynamic XML-based Web services. An X-RBAC system has been implemented as a Java application, and is based on a specification language that addresses specific security requirements of these Web services. We discuss the salient features of the specification language, and present the software architecture of our X-RBAC system.
引用
收藏
页码:243 / 249
页数:7
相关论文
共 50 条
  • [31] Active XML-based Web data integration
    Salem, Rashed
    Boussaid, Omar
    Darmont, Jerome
    INFORMATION SYSTEMS FRONTIERS, 2013, 15 (03) : 371 - 398
  • [32] A dynamic virtual organization solution for web-services based grid middleware
    Lee, YJ
    Sixteenth International Workshop on Database and Expert Systems Applications, Proceedings, 2005, : 40 - 44
  • [33] WReX: A scalable middleware architecture to enable XML caching for web-services
    Tatemura, J
    Po, O
    Sawires, A
    Agrawal, D
    Candan, KS
    MIDDLEWARE 2005, PROCEEDINGS, 2005, 3790 : 124 - 143
  • [34] Research of XML-Based Web Report System
    Liang, Kun
    Li, Yujun
    Duan, Jinghong
    Wang, Yiming
    2017 IEEE 3RD INTERNATIONAL CONFERENCE ON BIG DATA SECURITY ON CLOUD (BIGDATASECURITY, IEEE 3RD INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE AND SMART COMPUTING, (HPSC) AND 2ND IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT DATA AND SECURITY (IDS), 2017, : 96 - 100
  • [35] Lessons learned in using XML-based web services for dynamic near real-time environments in the department of defense
    Cherinka, R
    Wild, C
    Miller, R
    CCCT 2003, VOL 1, PROCEEDINGS: COMPUTING/INFORMATION SYSTEMS AND TECHNOLOGIES, 2003, : 306 - 311
  • [36] An XML-Based protocol for distributed event services
    Smith, W
    Gunter, D
    Quesnel, D
    PDPTA'2001: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, 2001, : 1668 - 1674
  • [37] Access control system using web services for XML messaging systems
    Kaplan, A
    Topcu, AE
    Pierce, M
    Fox, G
    IKE'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE ENGINEERING, VOLS 1 AND 2, 2003, : 207 - 211
  • [38] Secure web-based applications with XML and RBAC
    Yang, CG
    Zhang, CN
    IEEE SYSTEMS, MAN AND CYBERNETICS SOCIETY INFORMATION ASSURANCE WORKSHOP, 2003, : 276 - 281
  • [39] DS RBAC - Dynamic Sessions in Role Based Access Control
    Muehlbacher, Joerg R.
    Praher, Christian
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2009, 15 (03) : 538 - 554
  • [40] An XML-based framework for dynamic service management
    Shiaa, MM
    Jiang, S
    Supadulchai, P
    Vila-Armenegol, JJ
    INTELLIGENCE IN COMMUNICATION SYSTEMS, 2004, 3283 : 273 - 280