An access control model for web services in business process

被引:0
|
作者
Liu, P [1 ]
Chen, Z [1 ]
机构
[1] Peking Univ, Informat Secur Lab, Dept Comp Sci, Beijing 100871, Peoples R China
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Business process describes a set of services that span enterprise boundaries and are provided by enterprises that see each other as partners. Web services is widely accepted and adopted to construct business process. Web services are built in exposed environment and open to security threats. When a web service contained in a business process is authorized to illegal users, it will cause economic loss of the service provider. Although there exist some standards for security of Web services and access control for services in distributed systems are well studied, there is a lack of comprehensive approach in access control for web services, especially in business process. In this paper, an extended RBAC model, called WS-RBAC, is proposed to secure web services in business process. The model takes web services in business process as protected objects and extends the classical RBAC model. Next, The software architecture of WS-RABC is presented. This paper also presents how to specify business process in the model and the authorization constraints of WS-RBAC based on WS-Policy.
引用
收藏
页码:292 / 298
页数:7
相关论文
共 50 条
  • [1] A flexible access control model for Web services
    Bertino, E
    Squicciarini, AC
    FLEXIBLE QUERY ANSWERING SYSTEMS, PROCEEDINGS, 2004, 3055 : 13 - 16
  • [2] An adaptive access control model for Web services
    Bertino, Elisa
    Squicciarini, Anna C.
    Martino, Lorenzo
    Paci, Federica
    INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2006, 3 (03) : 27 - 60
  • [3] Access Control Model for Composite Web Services
    Jiang, Huangqin
    Zhang, Hongqi
    PROCEEDINGS OF 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY, 2012, : 684 - 688
  • [4] An extended RBAC model for web services in business process
    Liu, P
    Chen, Z
    PROCEEDINGS OF THE IEEE INTERNATIONAL CONFERENCE ON E-COMMERCE TECHNOLOGY FOR DYNAMIC E-BUSINESS, 2004, : 100 - 107
  • [5] ACCONV - An Access Control Model for Conversational Web Services
    Paci, Federica
    Mecella, Massimo
    Ouzzani, Mourad
    Bertino, Elisa
    ACM TRANSACTIONS ON THE WEB, 2011, 5 (03)
  • [6] Web services and business process management
    Leymann, F
    Roller, D
    Schmidt, MT
    IBM SYSTEMS JOURNAL, 2002, 41 (02) : 198 - 211
  • [7] Business process automation with web services
    Spath, D
    Rus, T
    Armbruster, M
    6TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL XX, PROCEEDINGS EXTENSION, 2002, : 204 - 208
  • [8] Business process integration with Web services
    Lee, J
    Kim, Y
    Kim, Y
    Moon, BH
    SIXTH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERNG, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING AND FIRST AICS INTERNATIONAL WORKSHOP ON SELF-ASSEMBLING WIRELESS NETWORKS, PROCEEDINGS, 2005, : 192 - 197
  • [9] An attribute-based access control model for Web services
    Shen Hai-bo
    Hong Fan
    SEVENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2006, : 74 - +
  • [10] Access control model for web services with attribute disclosure restriction
    Mewar, Vipin Singh
    Aich, Subhendu
    Sural, Shamik
    ARES 2007: SECOND INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2007, : 524 - +