Towards Web Service access control

被引:15
作者
Coetzee, M [1 ]
Eloff, JHP [1 ]
机构
[1] Univ Pretoria, Dept Comp Sci, ZA-0002 Pretoria, South Africa
基金
新加坡国家研究基金会;
关键词
SOAP; XML; access control; Web Services; assertions; authorisation manager; logical rules; roles; trust;
D O I
10.1016/j.cose.2004.05.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet has revolutionised the capacity to share information and services across organisations. Web Service technology enables organisations to exploit software as a service. Services are accessed by method invocations. Method interfaces are described and published, and may be freely available. Method requests and responses are conveyed in SOAP, which has the ability to pass unhindered through firewalls. Applications that process SOAP requests may be endangered by messages with malicious intent. Protection of methods and resources exposed by SOAP is thus a critical requirement for Web Services to be acceptable to organisations. In Web Service environments, access control is required to cross the borders of security domains, to be implemented between heterogeneous systems. New approaches are required that would address the movement of unknown users across borders so that access to resources can be granted. Specifications have been released to address access control, but are not welt established. In this paper, an analysis of current approaches to Web Service access control is made, which Leads to five requirements to be addressed by future access control solutions. To address such requirements, a logic-based access control approach is defined for 6 Web Service endpoint. The paper does not address the access control Logic that is required when more than one Web Service is used in an integrated business solution. (C) 2004 Elsevier Ltd. All rights reserved.
引用
收藏
页码:559 / 570
页数:12
相关论文
共 24 条
[1]  
[Anonymous], XML WEB SERVICES DAT
[2]  
[Anonymous], JAVA 2 PLATFORM
[3]  
ASHLEY P, 2000, P 7 ACM C COMP COMM, P220
[4]  
Bacon J, 2002, COMMUN ACM, V45, P59, DOI 10.1145/508448.508475
[5]  
BEZOSOV K, 1999, P 15 IEEE ANN COMP S, P310
[6]  
BHATTI R, 2003, 1 INT C WEB SERV LAS
[7]  
BLAZE M, 1999, KEYNOTE TRUST MANAGE
[8]  
Bonatti P. A., 2002, Journal of Computer Security, V10, P241
[9]  
BOX D, 2003, WEB SERVICES POLICY
[10]  
Box D., 2000, SIMPLE OBJECT ACCESS