An access control system for web service compositions

被引:0
|
作者
Srivatsa, Mudhakar [1 ]
Iyengar, Arun [2 ]
Mikalsen, Thomas [2 ]
Rouvellou, Isabelle [2 ]
Yin, Jian [2 ]
机构
[1] Georgia Inst Technol, Coll Comp, Atlanta, GA 30332 USA
[2] IBM Corp, Thomas J Watson Res Ctr, Yorktown Hts, NY 10598 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Service composition has emerged as a fundamental technique for developing Web applications. Multiple services, often from different organizations or trust domains, may be dynamically composed to satisfy a user's request. Access control in the presence of service compositions is a challenging security problem. In this paper, we present an access control model and techniques for specifying and enforcing access control rules on Web service compositions. A key advantage of our approach is that past histories of service invocations can be used to make access control decisions. Our approach allows role hierarchies and separation of duty constraints. Access controls rules may be parameterized by one or more arguments. We have implemented our access control model via a declarative policy specification language which uses pure-past linear temporal logic (PPLTL). We describe an implementation of our approach using a supply chain management (SCM) application. Our experiments show that our approach can enforce expressive and flexible access control policies while incurring reasonable performance overhead on the application.
引用
收藏
页码:1 / +
页数:2
相关论文
共 50 条
  • [31] Self-healing web service compositions
    Guinea, S
    ICSE 05: 27th International Conference on Software Engineering, Proceedings, 2005, : 655 - 655
  • [32] Timed modelling and analysis in web service compositions
    Kazhamiakin, Raman
    Pandya, Paritosh
    Pistore, Marco
    FIRST INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2006, : 840 - +
  • [33] Deploying fault tolerant web service compositions
    Laranjeiro, Nuno
    Vieira, Marco
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2008, 23 (05): : 337 - 348
  • [34] MANAGING TRANSACTIONAL COMPOSITIONS OF WEB SERVICE APPLICATIONS
    Puustjarvi, Juha
    WEBIST 2009: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, 2009, : 311 - 316
  • [35] An architecture for proactive timed web service compositions
    Eder, Johann
    Pichler, Horst
    Vielgut, Stefan
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, 2006, 4103 : 323 - 335
  • [36] Self-adaptive Web Service Compositions
    Baresi, Luciano
    EDOCW: 2008 12TH ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE WORKSHOPS, 2008, : 414 - 414
  • [37] Techniques to Produce Optimal Web Service Compositions
    Blanco, Eduardo
    Cardinale, Yudith
    Vidal, Maria-Esther
    Graterol, Jesus
    IEEE CONGRESS ON SERVICES 2008, PT I, PROCEEDINGS, 2008, : 553 - 558
  • [38] Computing performance requirements for web service compositions
    Garcia-Dominguez, Antonio
    Palomo-Lozano, Francisco
    Medina-Bulo, Inmaculada
    Ibias, Alfredo
    Nunez, Manuel
    COMPUTER STANDARDS & INTERFACES, 2023, 83
  • [39] Privacy-aware access control with trust management in web service
    Li, Min
    Sun, Xiaoxun
    Wang, Hua
    Zhang, Yanchun
    Zhang, Ji
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2011, 14 (04): : 407 - 430
  • [40] Uniform access control platform of web service based on semantic message
    Guan, Hua
    Ying, Shi
    Jia, Xiangyang
    Jiang, Caoqing
    INFORMATION SCIENCE AND MANAGEMENT ENGINEERING, VOLS 1-3, 2014, 46 : 927 - 934