ACCONV - An Access Control Model for Conversational Web Services

被引:9
|
作者
Paci, Federica [1 ]
Mecella, Massimo [2 ]
Ouzzani, Mourad [3 ]
Bertino, Elisa [4 ,5 ]
机构
[1] Univ Trent, Dept Informat Engn & Comp Sci, Trento, Italy
[2] Univ Roma La Sapienza, Dipartimento Informat & Sistemist Antonio Ruberti, Rome, Italy
[3] Qatar Fdn, Qatar Comp Res Inst, Doha, Qatar
[4] CERIAS, Cyber Ctr, W Lafayette, IN USA
[5] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
基金
欧盟第七框架计划;
关键词
Security; Web services; access control; conversations;
D O I
10.1145/1993053.1993055
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With organizations increasingly depending on Web services to build complex applications, security and privacy concerns including the protection of access control policies are becoming a serious issue. Ideally, service providers would like to make sure that clients have knowledge of only portions of the access control policy relevant to their interactions to the extent to which they are entrusted by the Web service and without restricting the client's choices in terms of which operations to execute. We propose ACCONV, a novel model for access control in Web services that is suitable when interactions between the client and the Web service are conversational and long-running. The conversation-based access control model proposed in this article allows service providers to limit how much knowledge clients have about the credentials specified in their access policies. This is achieved while reducing the number of times credentials are asked from clients and minimizing the risk that clients drop out of a conversation with the Web service before reaching a final state due to the lack of necessary credentials. Clients are requested to provide credentials, and hence are entrusted with part of the Web service access control policies, only for some specific granted conversations which are decided based on: (1) a level of trust that the Web service provider has vis-a-vis the client, (2) the operation that the client is about to invoke, and (3) meaningful conversations Which represent conversations that lead to a final state from the current one. We have implemented the proposed approach in a software prototype and conducted extensive experiments to show its effectiveness.
引用
下载
收藏
页数:33
相关论文
共 50 条
  • [41] A new method for consistency of access control in web services
    Bagheri, Esmaeil
    Babaei, Saeid
    Khayyambashi, Mohammad Reza
    2009 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, VOL 4, 2009, : 567 - +
  • [42] Web services access control architecture incorporating trust
    Coetzee, Marijke
    Eloff, J. H. P.
    INTERNET RESEARCH, 2007, 17 (03) : 291 - 305
  • [43] Verification of Access Control Requirements in Web Services Choreography
    Paci, Federica
    Ouzzani, Mourad
    Mecella, Massimo
    2008 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, VOL 1, 2008, : 5 - +
  • [44] A Model for Specification, Composition and Verification of Access Control Policies and Its Application to Web Services
    Derakhshandeh, Zahra
    Ladani, Behrouz Tork
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2011, 3 (02): : 103 - 120
  • [45] A Multi-Layer based Access Control Model for GIS Mobile Web Services
    Kim, Jangwon
    Jeong, Dongwon
    Baik, Doo-Kwon
    2009 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, 2009, : 77 - +
  • [46] Toward a Privacy Preserving HIPAA-compliant Access Control Model for Web Services
    Alshugran, Tariq
    Dichter, Julius
    2014 IEEE INTERNATIONAL CONFERENCE ON ELECTRO/INFORMATION TECHNOLOGY (EIT), 2014, : 163 - 167
  • [47] An Access Control Model for Web Databases
    Bouchahda-Ben Tekaya, Ahlem
    Le Thanh, Nhan
    Bouhoula, Adel
    Labbene-Ayachi, Faten
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXIV, PROCEEDINGS, 2010, 6166 : 287 - +
  • [48] A Context-Aware Semantic-Based Access Control Model for Mobile Web Services
    Shen, HaiBo
    Cheng, Yu
    ADVANCED RESEARCH ON COMPUTER SCIENCE AND INFORMATION ENGINEERING, 2011, 153 : 132 - 139
  • [49] An Extended XACML Model to Secure Biological Web Services using Access Control Policies.
    Nirmalrani, V
    Saravanan, P.
    Sakthivel, P.
    RESEARCH JOURNAL OF PHARMACEUTICAL BIOLOGICAL AND CHEMICAL SCIENCES, 2016, 7 (03): : 1459 - 1466
  • [50] A trust-based context-aware access control model for Web-services
    Bhatti, R
    Bertino, E
    Ghafoor, A
    DISTRIBUTED AND PARALLEL DATABASES, 2005, 18 (01) : 83 - 105