首页> 外文会议>International World Wide Web Conference; Edinburgh(GB) >Access Control Enforcement for Conversation-based Web Services
【24h】

Access Control Enforcement for Conversation-based Web Services

机译:基于会话的Web服务的访问控制实施

获取原文
获取原文并翻译 | 示例

摘要

Service Oriented Computing is emerging as the main approach to build distributed enterprise applications on the Web. The widespread use of Web services is hindered by the lack of adequate security and privacy support. In this paper, we present a novel framework for enforcing access control in conversation-based Web services. Our approach takes into account the conversational nature of Web services. This is in contrast with existing approaches to access control enforcement that assume a Web service as a set of independent operations. Furthermore, our approach achieves a tradeoff between the need to protect Web service's access control policies and the need to disclose to clients the portion of access control policies related to the conversations they are interested in. This is important to avoid situations where the client cannot progress in the conversation due to the lack of required security requirements. We introduce the concept of k-trustworthiness that defines the conversations for which a client can provide credentials maximizing the likelihood that it will eventually hit a final state.
机译:面向服务的计算正在成为在Web上构建分布式企业应用程序的主要方法。由于缺乏足够的安全性和隐私支持,阻碍了Web服务的广泛使用。在本文中,我们提出了一个新颖的框架,用于在基于会话的Web服务中强制执行访问控制。我们的方法考虑了Web服务的对话性质。这与将Web服务假定为一组独立操作的现有访问控制实施方法相反。此外,我们的方法在保护Web服务的访问控制策略的需求与向客户披露与他们感兴趣的对话相关的访问控制策略的一部分的需求之间进行了权衡。这对于避免客户端无法进行的情况非常重要。由于缺乏必需的安全性要求而导致在对话中。我们引入了k可信赖性的概念,该概念定义了客户端可以为其提供凭据的对话,从而最大程度地提高了其最终达到最终状态的可能性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号