An access control system for web service compositions

被引:0
|
作者
Srivatsa, Mudhakar [1 ]
Iyengar, Arun [2 ]
Mikalsen, Thomas [2 ]
Rouvellou, Isabelle [2 ]
Yin, Jian [2 ]
机构
[1] Georgia Inst Technol, Coll Comp, Atlanta, GA 30332 USA
[2] IBM Corp, Thomas J Watson Res Ctr, Yorktown Hts, NY 10598 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Service composition has emerged as a fundamental technique for developing Web applications. Multiple services, often from different organizations or trust domains, may be dynamically composed to satisfy a user's request. Access control in the presence of service compositions is a challenging security problem. In this paper, we present an access control model and techniques for specifying and enforcing access control rules on Web service compositions. A key advantage of our approach is that past histories of service invocations can be used to make access control decisions. Our approach allows role hierarchies and separation of duty constraints. Access controls rules may be parameterized by one or more arguments. We have implemented our access control model via a declarative policy specification language which uses pure-past linear temporal logic (PPLTL). We describe an implementation of our approach using a supply chain management (SCM) application. Our experiments show that our approach can enforce expressive and flexible access control policies while incurring reasonable performance overhead on the application.
引用
收藏
页码:1 / +
页数:2
相关论文
共 50 条
  • [1] An access control system for a web map management service
    Bertino, E
    Damiani, ML
    Momini, D
    14TH INTERNATIONAL WORKSHOP ON RESEARCH ISSUES ON DATA ENGINEERING: WEB SERVICES FOR E-COMMERCE AND E-GOVERNMENT APPLICATIONS, PROCEEDINGS, 2004, : 33 - 39
  • [2] Towards Web Service access control
    Coetzee, M
    Eloff, JHP
    COMPUTERS & SECURITY, 2004, 23 (07) : 559 - 570
  • [3] Handling Concurrency Control Problem in Web Service Compositions
    Sundar, Shyam S.
    Kanchana, R.
    2013 FOURTH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATIONS AND NETWORKING TECHNOLOGIES (ICCCNT), 2013,
  • [4] Static verification of control and data in web service compositions
    Kazhamiakin, Raman
    Pistore, Marco
    ICWS 2006: IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2006, : 83 - +
  • [5] Validation of web service compositions
    Baresi, L.
    Bianculli, D.
    Ghezzi, C.
    Guinea, S.
    Spoletini, P.
    IET SOFTWARE, 2007, 1 (06) : 219 - 232
  • [6] On completeness of web service compositions
    Shen, Zhongnan
    Su, Jianwen
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 800 - +
  • [7] Using Semantic Web Techniques to Implement Access Control for Web Service
    He, Zhengqiu
    Huang, Kangyu
    Wu, Lifa
    Li, Huabo
    Lai, Haiguang
    INFORMATION COMPUTING AND APPLICATIONS, PT 1, 2010, 105 : 258 - 266
  • [8] Types for Workflow Access Control in Web Service Context
    Lu, Yahui
    Zhang, Li
    2009 IEEE CONGRESS ON SERVICES (SERVICES-1 2009), VOLS 1 AND 2, 2009, : 621 - +
  • [9] A Web Service Architecture for Enforcing Access Control Policies
    Ardagna, Claudio Agostino
    Damiani, Ernesto
    di Vimercati, Sabrina De Capitani
    Samarati, Pierangela
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2006, 142 : 47 - 62
  • [10] Quality of Service management for Web service compositions
    Guimaraes Garcia, Diego Zuquim
    Felgar de Toledo, Maria Beatriz
    CSE 2008:11TH IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 189 - 196