首页> 外文期刊>Distributed and Parallel Databases >A Trust-Based Context-Aware Access Control Model for Web-Services
【24h】

A Trust-Based Context-Aware Access Control Model for Web-Services

机译:Web服务的基于信任的上下文感知访问控制模型

获取原文
获取原文并翻译 | 示例
           

摘要

A key challenge in Web services security is the design of effective access control schemes that can adequately meet the unique security challenges posed by the Web services paradigm. Despite the recent advances in Web based access control approaches applicable to Web services, there remain issues that impede the development of effective access control models for Web services environment. Amongst them are the lack of context-aware models for access control, and reliance on identity or capability-based access control schemes. Additionally, the unique service access control features required in Web services technology are not captured in existing schemes. In this paper, we motivate the design of an access control scheme that addresses these issues, and propose an extended, trust-enhanced version of our XML-based Role Based Access Control (X-RBAC) framework that incorporates trust and context into access control. We outline the configuration mechanism needed to apply our model to the Web services environment, and provide a service access control specification. The paper presents an example service access policy composed using our framework, and also describes the implementation architecture for the system.
机译:Web服务安全性的一个关键挑战是设计有效的访问控制方案,该方案必须能够充分满足Web服务范式带来的独特安全性挑战。尽管最近在适用于Web服务的基于Web的访问控制方法方面取得了进步,但仍有一些问题阻碍了针对Web服务环境的有效访问控制模型的开发。其中之一是缺少用于访问控制的上下文感知模型,以及对基于身份或基于功能的访问控制方案的依赖。此外,现有方案未捕获Web服务技术所需的唯一服务访问控制功能。在本文中,我们激励设计解决这些问题的访问控制方案,并提出基于XML的基于角色的访问控制(X-RBAC)框架的扩展,增强信任的版本,该框架将信任和上下文纳入访问控制。我们概述了将模型应用于Web服务环境所需的配置机制,并提供了服务访问控制规范。本文提供了使用我们的框架构成的示例服务访问策略,并描述了该系统的实现架构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号