An access control system for web service compositions

被引:0
|
作者
Srivatsa, Mudhakar [1 ]
Iyengar, Arun [2 ]
Mikalsen, Thomas [2 ]
Rouvellou, Isabelle [2 ]
Yin, Jian [2 ]
机构
[1] Georgia Inst Technol, Coll Comp, Atlanta, GA 30332 USA
[2] IBM Corp, Thomas J Watson Res Ctr, Yorktown Hts, NY 10598 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Service composition has emerged as a fundamental technique for developing Web applications. Multiple services, often from different organizations or trust domains, may be dynamically composed to satisfy a user's request. Access control in the presence of service compositions is a challenging security problem. In this paper, we present an access control model and techniques for specifying and enforcing access control rules on Web service compositions. A key advantage of our approach is that past histories of service invocations can be used to make access control decisions. Our approach allows role hierarchies and separation of duty constraints. Access controls rules may be parameterized by one or more arguments. We have implemented our access control model via a declarative policy specification language which uses pure-past linear temporal logic (PPLTL). We describe an implementation of our approach using a supply chain management (SCM) application. Our experiments show that our approach can enforce expressive and flexible access control policies while incurring reasonable performance overhead on the application.
引用
收藏
页码:1 / +
页数:2
相关论文
共 50 条
  • [21] A Context Based Dynamic Access Control Model for Web Service
    Shang, Chaowang
    Yang, Zongkai
    Liu, Qingtang
    Zhao, Chengling
    EUC 2008: PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING, VOL 2, WORKSHOPS, 2008, : 339 - 343
  • [22] Expressive and Deployable Access Control in Open Web Service Applications
    Ardagna, Claudio A.
    di Vimercati, Sabrina De Capitani
    Paraboschi, Stefano
    Pedrini, Eros
    Samarati, Pierangela
    Verdicchio, Mario
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2011, 4 (02) : 96 - 109
  • [23] Web Service Access Control Based on Browser Fingerprint Detection
    Liu Hui
    He Xudong
    Gao Fan
    Wang KaiLun
    Yuan Enze
    JOURNAL OF WEB ENGINEERING, 2021, 20 (05): : 1587 - 1621
  • [24] Semantics-based Access Control Approach for Web Service
    He, Zhengqiu
    Wu, Lifa
    Li, Huabo
    Lai, Haiguang
    Hong, Zheng
    JOURNAL OF COMPUTERS, 2011, 6 (06) : 1152 - 1161
  • [25] Remote Network Control System for Web Service
    Wang, Fang
    Liu, Chang
    Lin, Li
    GREEN POWER, MATERIALS AND MANUFACTURING TECHNOLOGY AND APPLICATIONS III, PTS 1 AND 2, 2014, 484-485 : 348 - 352
  • [26] The NExT system:: Towards true dynamic adaptations of semantic web service compositions
    Bernstein, Abraham
    Daenzer, Michael
    SEMANTIC WEB: RESEARCH AND APPLICATIONS, PROCEEDINGS, 2007, 4519 : 739 - +
  • [27] A Web script-based access control system using probability density function of service time
    Uemura, Satoshi
    Hiehata, Yasuhiko
    Koto, Hideyuki
    Nakamura, Hajime
    2011 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2011,
  • [28] A framework for the deployment of adaptable web service compositions
    Baresi, Luciano
    Di Nitto, Elisabetta
    Ghezzi, Carlo
    Guinea, Sam
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2007, 1 (01) : 75 - 91
  • [29] Integrating Behavioral Trust in Web Service Compositions
    Paradesi, Sharon
    Doshi, Prashant
    Swaika, Sonu
    2009 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, VOLS 1 AND 2, 2009, : 453 - 460
  • [30] Encoding requests to web service compositions as constraints
    Lazovik, A
    Aiello, M
    Gennari, R
    PRINCIPLES AND PRACTICE OF CONSTRAINT PROGRAMMING - CP 2005, PROCEEDINGS, 2005, 3709 : 782 - 786