A Web Service Architecture for Enforcing Access Control Policies

被引:17
|
作者
Ardagna, Claudio Agostino [1 ]
Damiani, Ernesto [1 ]
di Vimercati, Sabrina De Capitani [1 ]
Samarati, Pierangela [1 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, I-26013 Crema, Italy
关键词
Web Services; security; interoperability; distributed systems; XML;
D O I
10.1016/j.entcs.2004.09.044
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Web services represent a challenge and an opportunity for organizations wishing to expose product and services offerings through the Internet. The Web service technology provides an environment in which service providers and consumers can discover each other and conduct business transactions through the exchange of XML-based documents. However, any organization using XML and Web Services must ensure that only the right users, sending the appropriate XML content, can access their Web Services. Access control policy specification for controlling access to Web services is then becoming an emergent research area due to the rapid development of Web services in modern economy. This paper is an effort to understand the basic concepts for securing Web services and the requirements for implementing secure Web services. We describe the design and implementation of a Web service architecture for enforcing access control policies, the overall rationale and some specific choices of our design are discussed.
引用
收藏
页码:47 / 62
页数:16
相关论文
共 50 条
  • [21] On the Incoherencies in Web Browser Access Control Policies
    Singh, Kapil
    Moshchuk, Alexander
    Wang, Helen J.
    Lee, Wenke
    2010 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2010, : 463 - 478
  • [22] Specification of access control policies for web services
    Liu, Miao
    Zhang, Wei
    Liu, Huai-Liang
    CIS WORKSHOPS 2007: INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY WORKSHOPS, 2007, : 472 - 475
  • [23] Towards Web Service access control
    Coetzee, M
    Eloff, JHP
    COMPUTERS & SECURITY, 2004, 23 (07) : 559 - 570
  • [24] A Web Service Architecture for Decentralised Identity- and Attribute-based Access Control
    Hebig, Regina N.
    Meinel, Christoph
    Menzel, Michael
    Thomas, Ivonne
    Warschofsky, Robert
    2009 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, VOLS 1 AND 2, 2009, : 551 - 558
  • [25] A new key assignment scheme for enforcing complicated access control policies in hierarchy
    Lin, IC
    Hwang, MS
    Chang, CC
    FUTURE GENERATION COMPUTER SYSTEMS, 2003, 19 (04) : 457 - 462
  • [26] Developing and Enforcing Policies for Access Control, Resource Usage, and Adaptation - A Practical Approach
    Margheri, Andrea
    Masi, Massimiliano
    Pugliese, Rosario
    Tiezzi, Francesco
    WEB SERVICES AND FORMAL METHODS, WS-FM 2013, 2014, 8379 : 85 - 105
  • [27] Abstracting and enforcing Web service protocols
    Benatallah, B
    Casati, F
    Skogsrud, H
    Toumani, F
    INTERNATIONAL JOURNAL OF COOPERATIVE INFORMATION SYSTEMS, 2004, 13 (04) : 413 - 440
  • [28] Enforcing UCON Policies on the Enterprise Service Bus
    Gheorghe, Gabriela
    Mori, Paolo
    Crispo, Bruno
    Martinelli, Fabio
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2010, PT II, 2010, 6427 : 876 - +
  • [29] Discovery and Resolution of Anomalies in Web Access Control Policies
    Hu, Hongxin
    Ahn, Gail-Joon
    Kulkarni, Ketan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2013, 10 (06) : 341 - 354
  • [30] TorPolice: Towards Enforcing Service-Defined Access Policies for Anonymous Communication in the Tor Network
    Liu, Zhuotao
    Liu, Yushan
    Winter, Philipp
    Mittal, Prateek
    Hu, Yih-Chun
    2017 IEEE 25TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2017,