An access control model for web services in business process

被引:0
|
作者
Liu, P [1 ]
Chen, Z [1 ]
机构
[1] Peking Univ, Informat Secur Lab, Dept Comp Sci, Beijing 100871, Peoples R China
来源
IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE (WI 2004), PROCEEDINGS | 2004年
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Business process describes a set of services that span enterprise boundaries and are provided by enterprises that see each other as partners. Web services is widely accepted and adopted to construct business process. Web services are built in exposed environment and open to security threats. When a web service contained in a business process is authorized to illegal users, it will cause economic loss of the service provider. Although there exist some standards for security of Web services and access control for services in distributed systems are well studied, there is a lack of comprehensive approach in access control for web services, especially in business process. In this paper, an extended RBAC model, called WS-RBAC, is proposed to secure web services in business process. The model takes web services in business process as protected objects and extends the classical RBAC model. Next, The software architecture of WS-RABC is presented. This paper also presents how to specify business process in the model and the authorization constraints of WS-RBAC based on WS-Policy.
引用
收藏
页码:292 / 298
页数:7
相关论文
共 50 条
  • [11] An attribute and role based access control model for web services
    Liu, M
    Guo, HQ
    Su, JD
    PROCEEDINGS OF 2005 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-9, 2005, : 1302 - 1306
  • [12] A fine-grained access control model for Web services
    Bertino, E
    Squicciarini, AC
    Mevi, D
    2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 33 - 40
  • [13] A metadata-based access control model for web services
    Yague, MI
    Maña, A
    Lopez, J
    INTERNET RESEARCH, 2005, 15 (01) : 99 - 116
  • [14] Access control model for web services based on attribute certificate
    Jin, Li'na
    Jiang, Xinghao
    Li, Jianhua
    Jisuanji Gongcheng/Computer Engineering, 2006, 32 (16): : 136 - 138
  • [15] The hybrid model for web services security Access control and information flow control
    Kedjar, Saadia
    Tari, Abdelkamel
    2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 194 - +
  • [16] Access control for semantic web services
    Agarwal, S
    Sprick, B
    IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2004, : 770 - 773
  • [17] Access control on the composition of Web services
    Zhu, Junqiang
    Zhou, Yu
    Tong, Weiqin
    INTERNATIONAL CONFERENCE ON NEXT GENERATION WEB SERVICES PRACTICES, PROCEEDINGS, 2006, : 89 - +
  • [18] Web services in access, control, and pricing
    Zhang, Liang-Jie
    INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2006, 3 (03) : I - I
  • [19] Scalable access control for web services
    Swamynathan, Gayatri
    Close, Tyler
    Banerjee, Sujata
    McGeer, Rick
    Zhao, Ben
    Almeroth, Kevin
    C5 2007: FIFTH INTERNATIONAL CONFERENCE ON CREATING, CONNECTING AND COLLABORATING THROUGH COMPUTING, PROCEEDINGS, 2007, : 93 - +
  • [20] Semantic Access Control for Web Services
    Liu, Miao
    Xie, Dongqing
    Li, Peng
    Zhang, Xunlai
    Tang, Chunming
    NSWCTC 2009: INTERNATIONAL CONFERENCE ON NETWORKS SECURITY, WIRELESS COMMUNICATIONS AND TRUSTED COMPUTING, VOL 2, PROCEEDINGS, 2009, : 55 - +