Expressive and Deployable Access Control in Open Web Service Applications

被引:13
|
作者
Ardagna, Claudio A. [1 ]
di Vimercati, Sabrina De Capitani [1 ]
Paraboschi, Stefano [2 ]
Pedrini, Eros [1 ]
Samarati, Pierangela [1 ]
Verdicchio, Mario [2 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, I-26013 Crema, CR, Italy
[2] Univ Bergamo, Dipartimento Ingn Informaz & Metodi Matematici, I-24044 Dalmine, BG, Italy
关键词
Deployable access control; web services; credentials; security policy communication; XACML;
D O I
10.1109/TSC.2010.29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional access control solutions, based on preliminary identification and authentication of the access requester, are not adequate for the context of open web service systems, where servers generally do not have prior knowledge of the requesters. The research community has acknowledged such a paradigm shift and several investigations have been carried out for new approaches to regulate access control in open dynamic settings. Typically based on logic, such approaches, while appealing for their expressiveness, result not applicable in practice, where simplicity, efficiency, and consistency with consolidated technology are crucial. The eXtensible Access Control Markup Language (XACML) has established itself as the emerging technological solution for controlling access in an interoperable and flexible way. Although supporting the most common policy representation mechanisms and having acquired a significant spread in the research community and the industry, XACML still suffers from some limitations which impact its ability to support actual requirements of open web-based systems. In this paper, we provide a simple and effective formalization of novel concepts that have to be supported for enforcing the new access control paradigm needed in open scenarios, toward the aim of providing an expressive solution actually deployable with today's technology. We illustrate how the concepts of our model can be deployed in the XACML standard by exploiting its extension points for the definition of new functions, and introducing a dialog management framework to enable access control interactions between web service clients and servers.
引用
收藏
页码:96 / 109
页数:14
相关论文
共 50 条
  • [1] A design of Open Service Access Gateway for Converged Web service
    Yang, Jinhong
    Park, Hyojin
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 1807 - +
  • [2] Towards Web Service access control
    Coetzee, M
    Eloff, JHP
    COMPUTERS & SECURITY, 2004, 23 (07) : 559 - 570
  • [3] An access control system for web service compositions
    Srivatsa, Mudhakar
    Iyengar, Arun
    Mikalsen, Thomas
    Rouvellou, Isabelle
    Yin, Jian
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 1 - +
  • [4] Securing Web Applications with Predicate Access Control
    Yang, Zhaomo
    Levchenko, Kirill
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXI, DBSEC 2017, 2017, 10359 : 541 - 554
  • [5] Using Semantic Web Techniques to Implement Access Control for Web Service
    He, Zhengqiu
    Huang, Kangyu
    Wu, Lifa
    Li, Huabo
    Lai, Haiguang
    INFORMATION COMPUTING AND APPLICATIONS, PT 1, 2010, 105 : 258 - 266
  • [6] Types for Workflow Access Control in Web Service Context
    Lu, Yahui
    Zhang, Li
    2009 IEEE CONGRESS ON SERVICES (SERVICES-1 2009), VOLS 1 AND 2, 2009, : 621 - +
  • [7] A Web Service Architecture for Enforcing Access Control Policies
    Ardagna, Claudio Agostino
    Damiani, Ernesto
    di Vimercati, Sabrina De Capitani
    Samarati, Pierangela
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2006, 142 : 47 - 62
  • [8] An access control system for a web map management service
    Bertino, E
    Damiani, ML
    Momini, D
    14TH INTERNATIONAL WORKSHOP ON RESEARCH ISSUES ON DATA ENGINEERING: WEB SERVICES FOR E-COMMERCE AND E-GOVERNMENT APPLICATIONS, PROCEEDINGS, 2004, : 33 - 39
  • [9] A SRP based handler for Web service access control
    Silva, FO
    Pacheco, JAA
    Rosa, PF
    2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 57 - 62
  • [10] Web 2.0 Applications in Open Access Institutional Repositories of Asia
    Khan, Aasif Mohammad
    Loan, Fayaz Ahmad
    Andrabi, Syed Aasif Ahmad
    DESIDOC JOURNAL OF LIBRARY & INFORMATION TECHNOLOGY, 2022, 42 (03): : 149 - 153