Access control in dynamic XML-based web-services with X-RBAC

被引:0
|
作者
Bhatti, R [1 ]
Joshi, JBD [1 ]
Bertino, E [1 ]
Ghafoor, A [1 ]
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
关键词
XML; RBAC; access control; web-services;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Policy specification for securing Web services is fast emerging as a key research area due to rapid proliferation of Web services in modem day enterprise applications. Whilst the use of XML technology to support these Web services has resulted in their tremendous growth, it has also introduced a new set of security challenges specific to these Web services. Though there has been recent research in areas of XML-based document security, these challenges have not been addressed within the XML framework. In this paper, we present X-RBAC, an XML-based RBAC policy specification framework for enforcing access control in dynamic XML-based Web services. An X-RBAC system has been implemented as a Java application, and is based on a specification language that addresses specific security requirements of these Web services. We discuss the salient features of the specification language, and present the software architecture of our X-RBAC system.
引用
收藏
页码:243 / 249
页数:7
相关论文
共 50 条
  • [41] Resource Discovery in Web-services based Grids
    Kaur, Damandeep
    Sengupta, Jyotsna
    PROCEEDINGS OF WORLD ACADEMY OF SCIENCE, ENGINEERING AND TECHNOLOGY, VOL 25, 2007, 25 : 284 - +
  • [42] An XML-based quality of service enabling language for the Web
    Gu, XH
    Nahrstedt, K
    Yuan, WH
    Wichadakul, D
    Xu, DY
    JOURNAL OF VISUAL LANGUAGES AND COMPUTING, 2002, 13 (01): : 61 - 95
  • [43] New dynamic hierarchical RBAC model for web services
    Zhu, Yi-Qun
    Li, Jian-Hua
    Zhang, Quan-Hai
    Shanghai Jiaotong Daxue Xuebao/Journal of Shanghai Jiaotong University, 2007, 41 (05): : 783 - 787
  • [44] XML-Based Web Data Pattern Discovery and Extraction
    Jia, Rui
    Xu, Shicheng
    Peng, Chengbao
    INFORMATION COMPUTING AND APPLICATIONS, PT 1, 2012, 307 : 708 - 715
  • [45] XGuide -: A practical guide to XML-based Web engineering
    Kerer, C
    Kirda, E
    Krügel, C
    WEB ENGINEERING AND PEER TO PEER COMPUTING, 2002, 2376 : 104 - 117
  • [46] XML-based approach for fast prototyping of Web applications
    Navarro, A
    Fernandez-Manjon, B
    Fernandez-Valmayor, A
    Sierra, JL
    WEB ENGINEERING, PROCEEDINGS, 2003, 2722 : 241 - 244
  • [47] An XML-based wrapper generator for Web information extraction
    Liu, L
    Han, W
    Buttler, D
    Pu, C
    Tang, W
    SIGMOD RECORD, VOL 28, NO 2 - JUNE 1999: SIGMOD99: PROCEEDINGS OF THE 1999 ACM SIGMOD - INTERNATIONAL CONFERENCE ON MANAGEMENT OF DATA, 1999, : 540 - 543
  • [48] An XML-based security architecture for integrating single sign-on and rule-based access control in mobile and ubiquitous web environments
    Jeong, Jongil
    Shin, Dongil
    Shin, Dongkyoo
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: OTM 2006 WORKSHOPS, PT 2, PROCEEDINGS, 2006, 4278 : 1357 - +
  • [49] An XML-based active document for intelligent web applications
    Nam, CK
    Jang, GS
    Bae, JHJ
    EXPERT SYSTEMS WITH APPLICATIONS, 2003, 25 (02) : 165 - 176
  • [50] A XML-based framework for the development of web-based laboratories focused on control systems education
    Pastor, R
    Sánchez, J
    Dormido, S
    INTERNATIONAL JOURNAL OF ENGINEERING EDUCATION, 2003, 19 (03) : 445 - 454