An adaptive access control model for Web services

被引:11
|
作者
Bertino, Elisa [1 ]
Squicciarini, Anna C.
Martino, Lorenzo
Paci, Federica
机构
[1] Purdue Univ, W Lafayette, IN 47907 USA
[2] Univ Milan, I-20122 Milan, Italy
关键词
access control; authorization; security; trust negotiation; WSDL;
D O I
10.4018/jwsr.2006070102
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents an innovative access control model, referred to as Web service Access Control Version 1 (Ws-AC1), specifically tailored to Web services. The most distinguishing features of this model are the flexible granularity in protection objects and negotiation capabilities. Under Ws-AC1, an authorization can be associated with a single service and can speck for which parameter values the service can be authorized for use, thus providing a fine access control granularity. Ws-AC1 also supports coarse granularities in protection objects in that it provides the notion of service class under which several services can be grouped. Authorizations can then be associated with a service class and automatically propagated to each element in the class. The negotiation capabilities of Ws-AC1 are related to the negotiation of identity attributes and the service parameters. Identity attributes refer to information that a party requesting a service may need to submit in order to obtain the service. The access control policy model of Ws-AC1 supports the specification of policies in which conditions are stated, specifying the identity attributes to be provided and constraints on their values. In addition, conditions may also be specified against context parameters, such as time. To enhance privacy and security, the actual submission of these identity attributes is executed through a negotiation process. Parameters may also be negotiated when a subject requires use of a service with certain parameters values that, however, are not authorized under the policies in place. In this paper, we provide the formal definitions underlying our model and the relevant algorithms, such as the access control algorithm. We also present an encoding of our model in the Web Services Description Language (WSDL) standard for which we develop an extension, required to support Ws-AC1.
引用
收藏
页码:27 / 60
页数:34
相关论文
共 50 条
  • [1] A flexible access control model for Web services
    Bertino, E
    Squicciarini, AC
    [J]. FLEXIBLE QUERY ANSWERING SYSTEMS, PROCEEDINGS, 2004, 3055 : 13 - 16
  • [2] Access Control Model for Composite Web Services
    Jiang, Huangqin
    Zhang, Hongqi
    [J]. PROCEEDINGS OF 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY, 2012, : 684 - 688
  • [3] ACCONV - An Access Control Model for Conversational Web Services
    Paci, Federica
    Mecella, Massimo
    Ouzzani, Mourad
    Bertino, Elisa
    [J]. ACM TRANSACTIONS ON THE WEB, 2011, 5 (03)
  • [4] An access control model for web services in business process
    Liu, P
    Chen, Z
    [J]. IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE (WI 2004), PROCEEDINGS, 2004, : 292 - 298
  • [5] Access control model for web services with attribute disclosure restriction
    Mewar, Vipin Singh
    Aich, Subhendu
    Sural, Shamik
    [J]. ARES 2007: SECOND INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2007, : 524 - +
  • [6] An attribute-based access control model for Web services
    Shen Hai-bo
    Hong Fan
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2006, : 74 - +
  • [7] An attribute and role based access control model for web services
    Liu, M
    Guo, HQ
    Su, JD
    [J]. PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 1302 - 1306
  • [8] A metadata-based access control model for web services
    Yague, MI
    Maña, A
    Lopez, J
    [J]. INTERNET RESEARCH, 2005, 15 (01) : 99 - 116
  • [9] A fine-grained access control model for Web services
    Bertino, E
    Squicciarini, AC
    Mevi, D
    [J]. 2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 33 - 40
  • [10] The hybrid model for web services security Access control and information flow control
    Kedjar, Saadia
    Tari, Abdelkamel
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 194 - +