A Web Service Architecture for Enforcing Access Control Policies

被引:17
|
作者
Ardagna, Claudio Agostino [1 ]
Damiani, Ernesto [1 ]
di Vimercati, Sabrina De Capitani [1 ]
Samarati, Pierangela [1 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, I-26013 Crema, Italy
关键词
Web Services; security; interoperability; distributed systems; XML;
D O I
10.1016/j.entcs.2004.09.044
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Web services represent a challenge and an opportunity for organizations wishing to expose product and services offerings through the Internet. The Web service technology provides an environment in which service providers and consumers can discover each other and conduct business transactions through the exchange of XML-based documents. However, any organization using XML and Web Services must ensure that only the right users, sending the appropriate XML content, can access their Web Services. Access control policy specification for controlling access to Web services is then becoming an emergent research area due to the rapid development of Web services in modern economy. This paper is an effort to understand the basic concepts for securing Web services and the requirements for implementing secure Web services. We describe the design and implementation of a Web service architecture for enforcing access control policies, the overall rationale and some specific choices of our design are discussed.
引用
收藏
页码:47 / 62
页数:16
相关论文
共 50 条
  • [1] Field access analysis for enforcing access control policies
    Lehmann, Kathrin
    Thiemann, Peter
    EMERGING TRENDS IN INFORMATION AND COMMUNICATION SECURITY, PROCEEDINGS, 2006, 3995 : 337 - 351
  • [2] An Architecture for Enforcing End-to-End Access Control Over Web Applications
    Hicks, Boniface
    Rueda, Sandra
    King, Dave
    Moyer, Thomas
    Schiffman, Joshua
    Sreenivasan, Yogesh
    McDaniel, Patrick
    Jaeger, Trent
    SACMAT 2010: PROCEEDINGS OF THE 15TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2010, : 163 - 172
  • [3] Enforcing Role-Based Access Control Policies in Web Services with UML and OCL
    Sohr, Karsten
    Mustafa, Tanveer
    Bao, Xinyu
    Ahn, Gail-Joon
    24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 257 - +
  • [4] 3PAC: Enforcing access policies for web services
    van Bemmel, J
    Wegdam, M
    Lagerberg, K
    2005 IEEE International Conference on Web Services, Vols 1 and 2, Proceedings, 2005, : 589 - 596
  • [5] Modeling and Enforcing Access Control Policies for Smart Contracts
    Toberg, Jan-Philipp
    Schiffl, Jonas
    Reiche, Frederik
    Beckert, Bernhard
    Heinrich, Robert
    Reussner, Ralf
    2022 FOURTH IEEE INTERNATIONAL CONFERENCE ON DECENTRALIZED APPLICATIONS AND INFRASTRUCTURES (DAPPS 2022), 2022, : 38 - 47
  • [6] Specifying and enforcing constraints in dynamic access control policies
    Essaouini, Nada
    Cuppens, Frederic
    Cuppens-Boulahia, Nora
    El Kalam, Anas Abou
    2014 TWELFTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2014, : 290 - 297
  • [7] A flexible architecture for enforcing and composing policies in a service-oriented environment
    Goovaerts, Tom
    De Win, Bart
    Joosen, Wouter
    DISTRIBUTED APPLICATIONS AND INTEROPERABLE SYSTEMS, PROCEEDINGS, 2007, 4531 : 253 - +
  • [8] A flexible hierarchical access control mechanism enforcing extension policies
    Chang, Ya-Fen
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (02) : 189 - 201
  • [9] On the Practicality of Cryptographically Enforcing Dynamic Access Control Policies in the Cloud
    Garrison, William C., III
    Shull, Adam
    Myers, Steven
    Lee, Adam J.
    2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2016, : 819 - 838
  • [10] Modeling and enforcing access control policies in conversational user interfaces
    Elena Planas
    Salvador Martínez
    Marco Brambilla
    Jordi Cabot
    Software and Systems Modeling, 2023, 22 : 1925 - 1944