首页> 外文会议> >A Policy-Based Authorization Framework for Web Services: Integrating XGTRBAC and WS-Policy
【24h】

A Policy-Based Authorization Framework for Web Services: Integrating XGTRBAC and WS-Policy

机译:Web服务的基于策略的授权框架:集成XGTRBAC和WS-Policy

获取原文
获取外文期刊封面目录资料

摘要

Authorization and access control in Web services is complicated by the unique requirements of the dynamic Web services paradigm. Current authentication mechanisms for Web services do not differentiate between users in terms of fine-grained access privileges. This results in an all-or-nothing access which is not flexible enough for modern day business processes using Web services to execute. In this paper, we present a policy-based authorization framework to address this requirement. We have designed a profile of the well-known WS-Policy specification tailored to meet the access control requirements in Web services by integrating WS-Policy with an access control policy specification language, X-GTRBAC. The design of the profile is aimed at bridging the gap between available policy standards for Web services and existing policy specification languages for access control. The profile supports the WS-Policy Attachment specification, which allows separate policies to be associated with multiple components of a Web service description, and one of our key contributions is the design of an algorithm to compute the effective policy for the Web service given the multiple policy attachments. To allow Web service applications to use our solution, we have adopted a component-based design approach based on well-known UML notations. We have also prototyped our architecture, and implemented it as a loosely coupled Web service providing healthcare information services to physicians subject to applicable authorization policies.
机译:动态Web服务范例的独特要求使Web服务中的授权和访问控制变得复杂。当前的Web服务身份验证机制无法根据细粒度的访问特权在用户之间进行区分。这将导致全部访问或全部访问,这对于使用Web服务执行的现代业务流程来说不够灵活。在本文中,我们提出了一个基于策略的授权框架来解决这一要求。我们通过将WS-Policy与访问控制策略规范语言X-GTRBAC集成在一起,设计了众所周知的WS-Policy规范的概要文件,该规范旨在满足Web服务中的访问控制要求。概要文件的设计旨在弥合Web服务的可用策略标准与访问控制的现有策略规范语言之间的差距。该概要文件支持WS-Policy Attachment规范,该规范允许将单独的策略与Web服务描述的多个组件相关联,并且我们的主要贡献之一是设计一种算法,该算法可以在给定多个Web服务描述的情况下为Web服务计算有效策略政策附件。为了使Web服务应用程序能够使用我们的解决方案,我们采用了基于组件的设计方法,该方法基于众所周知的UML表示法。我们还对我们的体系结构进行了原型设计,并将其实现为松散耦合的Web服务,以根据适用的授权策略为医生提供医疗保健信息服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号