A trust-based context-aware access control model for Web-services

被引:69
作者
Bhatti, R [1 ]
Bertino, E
Ghafoor, A
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
[2] Purdue Univ, CERIAS, W Lafayette, IN 47907 USA
[3] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
基金
美国国家科学基金会;
关键词
XML; Role-Based Access Control; Trust Management; Web services;
D O I
10.1007/s10619-005-1075-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A key challenge in Web services security is the design of effective access control schemes that can adequately meet the unique security challenges posed by the Web services paradigm. Despite the recent advances in Web based access control approaches applicable to Web services, there remain issues that impede the development of effective access control models for Web services environment. Amongst them are the lack of context-aware models for access control, and reliance on identity or capability-based access control schemes. Additionally, the unique service access control features required in Web services technology are not captured in existing schemes. In this paper, we motivate the design of an access control scheme that addresses these issues, and propose an extended, trust-enhanced version of our XML-based Role Based Access Control (X-RBAC) framework that incorporates trust and context into access control. We outline the configuration mechanism needed to apply our model to the Web services environment, and provide a service access control specification. The paper presents an example service access policy composed using our framework, and also describes the implementation architecture for the system.
引用
收藏
页码:83 / 105
页数:23
相关论文
共 16 条
[1]  
[Anonymous], P 2002 IEEE S SEC PR
[2]  
[Anonymous], 2704 IETF RFC
[3]  
BERTINO E, 2001, IEEE INTERNET CO MAY
[4]  
BHATTI R, 2003, THESIS PURDUE U
[5]  
BHATTI R, 2004, P 9 ACM S ACC CONTR
[6]  
Bhatti R., 2003, P 1 INT C WEB SERV L
[7]  
DAMIANI E, 2002, ACM T INFORMATION SY, V5
[8]  
Dimmock N, 2004, P 9 ACM S ACC CONTR
[9]  
FERRAIOLO D, 2001, ACM T INFORMATION SY, V4
[10]  
HADA S, 2000, IBM RES OCT