A Scalable and Flexible Web Services Authentication Model

被引:0
|
作者
Felix, Pedro [1 ]
Ribeiro, Carlos [1 ]
机构
[1] Inst Super Engn Lisboa, P-1959007 Lisbon, Portugal
关键词
Web Services Security; Authentication; Trust Management;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The WS-* specification set defines a message authentication model for web services. This model targets the authentication of messages exchanges in large scale decentralized systems, composed by different authentication domains. However, it has scalability and flexibility limitations: the acquirement of identity claims requires online interactions with security token services, which introduces communication overhead and creates performance bottlenecks; the services' policies, containing its requirements, must directly point to the issuing security token services, limiting the flexibility of the trust relations. We present a new model, addressing these limitations, using two concepts from the trust management paradigm: credentials for claim inference and claim-based issuer references (attribute based delegation). We show how credentials are used both to increase the scalability, reducing the number of online token requests, and to increase the flexibility by allowing indirect trust relations, namely claim based delegation. We also show how the simultaneous usage of security tokens and credentials results in several advantages of our model, when compared to credential only trust management models. The proposed model fits nicely into the WS-* framework, namely into its message security model and policy language. We illustrate this with the implementation of an extension to the Windows Communication Foundation - a commercial grade web services platform - that provides support for this model.
引用
收藏
页码:66 / 72
页数:7
相关论文
共 50 条
  • [1] Architectures for scalable and flexible Web personalization services
    Canali, Claudia
    Casolari, Sara
    Lancellotti, Riccardo
    [J]. FIRST INTERNATIONAL WORKSHOP ON ADVANCED ARCHITECTURES AND ALGORITHMS FOR INTERNET DELIVERY AND APPLICATIONS, PROCEEDINGS, 2006, : 50 - +
  • [2] Robust remote authentication for scalable web-based services
    Li, Jianbin
    Lam, Kwok-Yan
    Sun, Hong-Wei
    Chung, Siu-Leung
    [J]. 2008 FOURTH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING, PROCEEDINGS, 2008, : 1113 - 1117
  • [3] A distributed authentication model for composite Web services
    Nacer, Hassina
    Djebari, Nabil
    Slimani, Hachem
    Aissani, Djamil
    [J]. COMPUTERS & SECURITY, 2017, 70 : 144 - 178
  • [4] A flexible model for locating services on the web
    Lara, Ruben
    Corella, Miguel Angel
    Castells, Pablo
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC COMMERCE, 2007, 12 (02) : 11 - 40
  • [5] A flexible and scalable framework for QoS-aware web services composition
    Hosseinpour Agdam M.
    Yousefi S.
    [J]. 2010 5th International Symposium on Telecommunications, IST 2010, 2010, : 521 - 526
  • [6] A flexible access control model for Web services
    Bertino, E
    Squicciarini, AC
    [J]. FLEXIBLE QUERY ANSWERING SYSTEMS, PROCEEDINGS, 2004, 3055 : 13 - 16
  • [7] Towards scalable authentication in health services
    Ahn, GJ
    Shin, D
    [J]. WET ICE 2002: ELEVENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2002, : 83 - 88
  • [8] Authentication and Authorization in Web Services
    Challita, Khalil
    Farhat, Hikmat
    Zalaket, Joseph
    [J]. NETWORKED DIGITAL TECHNOLOGIES, 2011, 136 : 13 - 23
  • [9] A semantics for web services authentication
    Bhargavan, K
    Fournet, C
    Gordon, AD
    [J]. THEORETICAL COMPUTER SCIENCE, 2005, 340 (01) : 102 - 153
  • [10] A semantics for web services authentication
    Bhargavan, K
    Fournet, C
    Gordon, AD
    [J]. ACM SIGPLAN NOTICES, 2004, 39 (01) : 198 - 209