首页> 外文会议>IEEE International Conference on Web Services >A Policy-Based Authorization Framework for Web Services: Integrating X-GTRBAC and WS-Policy
【24h】

A Policy-Based Authorization Framework for Web Services: Integrating X-GTRBAC and WS-Policy

机译:基于策略的Web服务授权框架:集成X-Gtrbac和WS-Policy

获取原文

摘要

Authorization and access control in Web services is complicated by the unique requirements of the dynamic Web services paradigm. Current authentication mechanisms for Web services do not differentiate between users in terms of fine-grained access privileges. This results in an all-or-nothing access which is not flexible enough for modern day business processes using Web services to execute. In this paper, we present a policy-based authorization framework to address this requirement. We have designed a profile of the well-known WS-Policy specification tailored to meet the access control requirements in Web services by integrating WS-Policy with an access control policy specification language, X-GTRBAC. The design of the profile is aimed at bridging the gap between available policy standards for Web services and existing policy specification languages for access control. The profile supports the WS-Policy Attachment specification, which allows separate policies to be associated with multiple components of a Web service description, and one of our key contributions is the design of an algorithm to compute the effective policy for the Web service given the multiple policy attachments. To allow Web service applications to use our solution, we have adopted a component-based design approach based on well-known UML notations. We have also prototyped our architecture, and implemented it as a loosely coupled Web service providing healthcare information services to physicians subject to applicable authorization policies.
机译:Web服务中的授权和访问控制因动态Web服务范例的独特要求而复杂。在细粒度访问权限方面,Web服务的当前身份验证机制不会区分用户。这导致全无或无限的访问,这对于使用Web服务执行的现代业务流程不够灵活。在本文中,我们提出了一个基于策略的授权框架来解决此要求。我们设计了众所周知的WS-Policy规范,通过将WS-Policy与Access Control策略规范语言X-GtrBac集成了Web服务中的访问控制要求,以满足Web服务中的访问控制要求。配置文件的设计旨在弥合可用的Web服务策略标准与访问控制的现有策略规范语言之间的差距。该配置文件支持WS-Policy附件规范,它允许单独的策略与Web服务描述的多个组件相关联,以及我们的主要贡献之一是计算给定多个算法计算Web服务的有效策略的算法政策附件。为了允许Web服务应用程序使用我们的解决方案,我们采用了一种基于众所周知的UML符号的组件的设计方法。我们也已将我们的架构设计,并将其实施为一个松散耦合的Web服务,为受适用授权政策的医生提供医疗服务提供医疗信息服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号