The hybrid model for web services security Access control and information flow control

被引:0
|
作者
Kedjar, Saadia [1 ]
Tari, Abdelkamel [2 ]
机构
[1] Univ Bejaia, Dept Comp Sci, Bejaia, Algeria
[2] Univ Bejaia, Lab Appl Math LMA, Bejaia, Algeria
关键词
web services security; Access control; Information flow control; trust management in web services;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The openness and accessibility of the web Services on the Internet makes them vulnerable to various attacks. Therefore, security solutions are necessary to restrict access to web services and objects they manipulate. In this paper, we propose a hybrid model that incorporates a mechanism for access control (AC) and a mechanism for information flow control (IFC). The AC mechanism controls user access to web services methods and uses the concept of role to represent a functionality of web services methods and attributes for trust management between service providers and requesters. The IFC mechanism associates labels to the objects of the system to control access to them and verify information flows between these objects to ensure the information confidentiality and integrity.
引用
收藏
页码:194 / +
页数:3
相关论文
共 50 条
  • [1] Access Control and Information Flow Control for Web Services Security
    Kedjar, Saadia
    Tari, Abdelkamel
    Bertok, Peter
    [J]. INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2016, 11 (01) : 44 - 76
  • [2] A double access control model for web services based information system
    Chen, Xueqin
    Wu, Huizhong
    Zhu, Yaoqin
    [J]. 2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 2, 2008, : 1045 - 1050
  • [3] Lightweight Information Flow Control for Web Services
    Brodecki, Bartosz
    Kalewski, Michal
    Sasak, Piotr
    Szychowiak, Michal
    [J]. PARALLEL PROCESSING AND APPLIED MATHEMATICS, PT II, 2012, 7204 : 608 - 617
  • [4] A flexible access control model for Web services
    Bertino, E
    Squicciarini, AC
    [J]. FLEXIBLE QUERY ANSWERING SYSTEMS, PROCEEDINGS, 2004, 3055 : 13 - 16
  • [5] An adaptive access control model for Web services
    Bertino, Elisa
    Squicciarini, Anna C.
    Martino, Lorenzo
    Paci, Federica
    [J]. INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2006, 3 (03) : 27 - 60
  • [6] Access Control Model for Composite Web Services
    Jiang, Huangqin
    Zhang, Hongqi
    [J]. PROCEEDINGS OF 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY, 2012, : 684 - 688
  • [7] An Access Control Framework to Support Security in Web Services Interoperability
    Movahednejad, Homa
    Tabatabaei, Sayed Gholam Hassan
    Sharifi, Mandi
    Ibrahim, Suhaimi
    [J]. CREATING GLOBAL ECONOMIES THROUGH INNOVATION AND KNOWLEDGE MANAGEMENT: THEORY & PRACTICE, VOLS 1-3, 2009, : 1434 - 1441
  • [8] Hybrid Access Control Model in Semantic Web
    Verma, Sonu
    Kumar, Suresh
    Singh, Manjeet
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (06): : 92 - 97
  • [9] ACCONV - An Access Control Model for Conversational Web Services
    Paci, Federica
    Mecella, Massimo
    Ouzzani, Mourad
    Bertino, Elisa
    [J]. ACM TRANSACTIONS ON THE WEB, 2011, 5 (03)
  • [10] An access control model for web services in business process
    Liu, P
    Chen, Z
    [J]. IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE (WI 2004), PROCEEDINGS, 2004, : 292 - 298