首页> 外文会议>IEEE International Conference on Web Services >A Web Service Architecture for Decentralised Identity- and Attribute-Based Access Control
【24h】

A Web Service Architecture for Decentralised Identity- and Attribute-Based Access Control

机译:基于分散的Identity和基于属性的访问控制的Web服务架构

获取原文

摘要

The loosely coupled nature of service-oriented architectures raises the question how information for access control can be managed in an efficient way. Several specifications for Web services exist to describe security requirements and to facilitate a provision of identity information. However, the integration of different standards regarding the expression of identity information in policies, claims and assertions comes along with an increased complexity. In order to identify and address the problems occurring with the combined use of standards as XACML, SAML and WS-Trust, we designed and implemented an architecture for identity- and attribute-based access control in decentralized environments. Our implementation provides an automated generation of access control policies in a format called XACML, a way to communicate required user attributes as claims across different domains based on the standards WS-Trust and WS-Policy, and a consistent mapping of retrieved attribute assertions to the XACML attributes in the access control policy.
机译:面向服务的架构的松散耦合性质提出了如何以有效的方式管理访问控制的信息。存在用于Web服务的几种规范来描述安全要求,并促进提供身份信息。但是,关于政策,声明和断言在政策中的身份信息表达的不同标准的整合随着复杂性的增加。为了识别和解决与XACML,SAML和WS-Trust的合并使用标准进行的问题,我们设计并实现了分散环境中基于Identity和属性的访问控制的体系结构。我们的实现提供了一种名为XACML的格式的自动生成访问控制策略,一种方式将所需的用户属性传送到不同域的索引,其基于标准WS-Trust和WS-Policy的不同域,以及对其检索的属性断言的一致映射访问控制策略中的XACML属性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号