An access control model for web services in business process

被引:0
|
作者
Liu, P [1 ]
Chen, Z [1 ]
机构
[1] Peking Univ, Informat Secur Lab, Dept Comp Sci, Beijing 100871, Peoples R China
来源
IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE (WI 2004), PROCEEDINGS | 2004年
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Business process describes a set of services that span enterprise boundaries and are provided by enterprises that see each other as partners. Web services is widely accepted and adopted to construct business process. Web services are built in exposed environment and open to security threats. When a web service contained in a business process is authorized to illegal users, it will cause economic loss of the service provider. Although there exist some standards for security of Web services and access control for services in distributed systems are well studied, there is a lack of comprehensive approach in access control for web services, especially in business process. In this paper, an extended RBAC model, called WS-RBAC, is proposed to secure web services in business process. The model takes web services in business process as protected objects and extends the classical RBAC model. Next, The software architecture of WS-RABC is presented. This paper also presents how to specify business process in the model and the authorization constraints of WS-RBAC based on WS-Policy.
引用
收藏
页码:292 / 298
页数:7
相关论文
共 50 条
  • [31] Specification of access control policies for web services
    Liu, Miao
    Zhang, Wei
    Liu, Huai-Liang
    CIS WORKSHOPS 2007: INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY WORKSHOPS, 2007, : 472 - 475
  • [32] Business process management: Where business processes and web services meet
    van der Aalst, Wil M. P.
    Benatallah, Boualem
    Casati, Fabio
    Curbera, Francisco
    Verbeek, Eric
    DATA & KNOWLEDGE ENGINEERING, 2007, 61 (01) : 1 - 5
  • [33] Enabling Business Experts to Discover Web Services for Business Process Automation
    Stein, Sebastian
    Barchewitz, Katja
    El Kharbili, Marwane
    EMERGING WEB SERVICES TECHNOLOGY, VOL II, 2008, 2 : 23 - +
  • [34] DEVELOPMENT OF A BUSINESS MODEL FOR SOCIAL WEB OF SERVICES
    Komarov, Mikhail M.
    Khokhlova, Anna D.
    BIZNES INFORMATIKA-BUSINESS INFORMATICS, 2015, 32 (02): : 20 - 29
  • [35] An Access Control Model for Web-Services that Supports Delegation and Creation of Authority
    Mabuchi, Mitsuhiro
    Shinjo, Yasushi
    Sato, Akira
    Kato, Kazuhiko
    ICN 2008: SEVENTH INTERNATIONAL CONFERENCE ON NETWORKING, PROCEEDINGS, 2008, : 213 - 222
  • [36] Analysis of Business Process Models in Enterprise Web Services
    Kung, Mabel T.
    Zhang, Jenny Yi
    INTERNATIONAL JOURNAL OF E-BUSINESS RESEARCH, 2008, 4 (02) : 69 - 87
  • [37] Approach based on web services for business process adaptation
    Awadid, Afef
    Gnannouchi, Sonia Ayachi
    CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS/INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT/CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES, CENTERIS/PROJMAN / HCIST 2015, 2015, 64 : 832 - 837
  • [38] The Research of Access Process in Web Services Based on XACML
    Dai, Changying
    Gong, Wentao
    Liu, Jing
    2010 2ND INTERNATIONAL WORKSHOP ON DATABASE TECHNOLOGY AND APPLICATIONS PROCEEDINGS (DBTA), 2010,
  • [39] Business Process Execution From the Alignment Between Business Processes and Web Services: A Semantic and Model-Driven Modernization Process
    Sosa Sanchez, Encarna
    Clemente, Pedro J.
    Conejero, Jose M.
    Prieto, Alvaro E.
    IEEE ACCESS, 2020, 8 (08): : 93346 - 93368
  • [40] Access Control and Information Flow Control for Web Services Security
    Kedjar, Saadia
    Tari, Abdelkamel
    Bertok, Peter
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2016, 11 (01) : 44 - 76