Expressive and Deployable Access Control in Open Web Service Applications

被引:13
|
作者
Ardagna, Claudio A. [1 ]
di Vimercati, Sabrina De Capitani [1 ]
Paraboschi, Stefano [2 ]
Pedrini, Eros [1 ]
Samarati, Pierangela [1 ]
Verdicchio, Mario [2 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, I-26013 Crema, CR, Italy
[2] Univ Bergamo, Dipartimento Ingn Informaz & Metodi Matematici, I-24044 Dalmine, BG, Italy
关键词
Deployable access control; web services; credentials; security policy communication; XACML;
D O I
10.1109/TSC.2010.29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional access control solutions, based on preliminary identification and authentication of the access requester, are not adequate for the context of open web service systems, where servers generally do not have prior knowledge of the requesters. The research community has acknowledged such a paradigm shift and several investigations have been carried out for new approaches to regulate access control in open dynamic settings. Typically based on logic, such approaches, while appealing for their expressiveness, result not applicable in practice, where simplicity, efficiency, and consistency with consolidated technology are crucial. The eXtensible Access Control Markup Language (XACML) has established itself as the emerging technological solution for controlling access in an interoperable and flexible way. Although supporting the most common policy representation mechanisms and having acquired a significant spread in the research community and the industry, XACML still suffers from some limitations which impact its ability to support actual requirements of open web-based systems. In this paper, we provide a simple and effective formalization of novel concepts that have to be supported for enforcing the new access control paradigm needed in open scenarios, toward the aim of providing an expressive solution actually deployable with today's technology. We illustrate how the concepts of our model can be deployed in the XACML standard by exploiting its extension points for the definition of new functions, and introducing a dialog management framework to enable access control interactions between web service clients and servers.
引用
收藏
页码:96 / 109
页数:14
相关论文
共 50 条
  • [21] Web Service Access Control Based on Browser Fingerprint Detection
    Liu Hui
    He Xudong
    Gao Fan
    Wang KaiLun
    Yuan Enze
    JOURNAL OF WEB ENGINEERING, 2021, 20 (05): : 1587 - 1621
  • [22] Semantics-based Access Control Approach for Web Service
    He, Zhengqiu
    Wu, Lifa
    Li, Huabo
    Lai, Haiguang
    Hong, Zheng
    JOURNAL OF COMPUTERS, 2011, 6 (06) : 1152 - 1161
  • [23] Web analytics in open access academic journals: justification, planning and applications
    Vitela Caraveo, Alex
    Urbano, Cristobal
    BID-TEXTOS UNIVERSITARIS DE BIBLIOTECONOMIA I DOCUMENTACIO, 2020, (45):
  • [24] An Integrated Access Control Service Enabler for Cloud Applications
    Tran Quang Thanh
    Covaci, Stefan
    Ertl, Benjamin
    Zampognano, Paolo
    FUTURE NETWORK SYSTEMS AND SECURITY, FNSS 2015, 2015, 523 : 101 - 112
  • [25] Cross-platform access control for mobile web applications
    Lyle, John
    Monteleone, Salvatore
    Faily, Shamal
    Patti, Davide
    Ricciato, Fabio
    Proceedings - 2012 IEEE International Symposium on Policies for Distributed Systems and Networks, POLICY 2012, 2012, : 37 - 44
  • [26] Supporting Maintenance and Evolution of Access Control Models in Web Applications
    Gauthier, Francois
    Merlo, Ettore
    Stroulia, Eleni
    Turner, David
    2014 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2014, : 506 - 510
  • [27] Privacy-aware access control with trust management in web service
    Li, Min
    Sun, Xiaoxun
    Wang, Hua
    Zhang, Yanchun
    Zhang, Ji
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2011, 14 (04): : 407 - 430
  • [28] Uniform access control platform of web service based on semantic message
    Guan, Hua
    Ying, Shi
    Jia, Xiangyang
    Jiang, Caoqing
    INFORMATION SCIENCE AND MANAGEMENT ENGINEERING, VOLS 1-3, 2014, 46 : 927 - 934
  • [29] An Access Control Approach of Multi_Security Domain for Web Service
    Guo, Song
    Lai, Xiaoping
    CEIS 2011, 2011, 15
  • [30] Embedding Access Control Policy in Web Service Path Composition Algorithm
    Chou, Shih-Chien
    Jhu, Jin-Yuan
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2011, 27 (06) : 1839 - 1853