An access control model for web services in business process

被引:0
|
作者
Liu, P [1 ]
Chen, Z [1 ]
机构
[1] Peking Univ, Informat Secur Lab, Dept Comp Sci, Beijing 100871, Peoples R China
来源
IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE (WI 2004), PROCEEDINGS | 2004年
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Business process describes a set of services that span enterprise boundaries and are provided by enterprises that see each other as partners. Web services is widely accepted and adopted to construct business process. Web services are built in exposed environment and open to security threats. When a web service contained in a business process is authorized to illegal users, it will cause economic loss of the service provider. Although there exist some standards for security of Web services and access control for services in distributed systems are well studied, there is a lack of comprehensive approach in access control for web services, especially in business process. In this paper, an extended RBAC model, called WS-RBAC, is proposed to secure web services in business process. The model takes web services in business process as protected objects and extends the classical RBAC model. Next, The software architecture of WS-RABC is presented. This paper also presents how to specify business process in the model and the authorization constraints of WS-RBAC based on WS-Policy.
引用
收藏
页码:292 / 298
页数:7
相关论文
共 50 条
  • [41] Application of integrated web services-based e-business and web services-based business process monitoring
    Dong, JC
    Yue, WY
    INTERNET AND NETWORK ECONOMICS, PROCEEDINGS, 2005, 3828 : 375 - 384
  • [42] Secure communication and access control for web services container
    Peng, Yu
    Wu, Quanyuan
    GCC 2005: FIFTH INTERNATIONAL CONFERENCE ON GRID AND COOPERATIVE COMPUTING, PROCEEDINGS, 2006, : 412 - +
  • [43] Role-based access control for web services
    College of Information Sciences and Technology, Donghua University, 1882 Yan'an Road , Shanghai 200051, China
    WSEAS Trans. Inf. Sci. Appl., 2006, 8 (1553-1558):
  • [44] Action-Based Access Control for Web Services
    Li, Fenghua
    Wang, Wei
    Ma, Jianfeng
    Su, Haoxin
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 637 - 642
  • [45] A context-aware role-based access control model for Web services
    Shen, HB
    Hong, F
    ICEBE 2005: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2005, : 220 - 223
  • [46] Context-aware role-based access control model for Web services
    Feng, X
    Jun, M
    Hao, H
    Li, X
    GRID AND COOPERATIVE COMPUTING GCC 2004 WORKSHOPS, PROCEEDINGS, 2004, 3252 : 430 - 436
  • [47] A Semantic-Aware Attribute-Based Access Control Model for Web Services
    Shen, Haibo
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, PROCEEDINGS, 2009, 5574 : 693 - 703
  • [48] User tasks and access control over web services
    Thomas, Jacques
    Paci, Federica
    Bertino, Elisa
    Eugster, Patrick
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 60 - +
  • [49] A platform independent access control metamodel for web services
    Simon, Balázs
    Goldschmidt, Balázs
    Kondorosi, Károly
    Periodica polytechnica Electrical engineering and computer science, 2014, 58 (03): : 93 - 108
  • [50] Attributed based access control (ABAC) for web services
    Yuan, E
    Tong, J
    2005 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, VOLS 1 AND 2, PROCEEDINGS, 2005, : 561 - 569