首页> 外文期刊>International Journal of Computer Systems Science & Engineering >A comparison of modeling strategies in defining XML-based access control languages
【24h】

A comparison of modeling strategies in defining XML-based access control languages

机译:定义基于XML的访问控制语言时建模策略的比较

获取原文
获取原文并翻译 | 示例
       

摘要

One of the most important features of XML-based Web services is that they can be easily accessed over the Internet, but this makes them vulnerable toa series of security threats. What makes security for web services so challenging is their distributed and heterogeneous nature. Access control policy specification for controlling access to Web services is then becoming an emergent research area due to the rapid development of Web services in modern economy. Two relevant access control languages using XML are WS-Policy and XACML. The main conceptual difference between these two languages is that while XACML is based on a well-defined model that provides a formal representation of the access control security policy and its working, WS-Policy has been developed without taking into consideration this modeling phase. In this paper, we critique WS-Policy pointing out some of its shortcomings. We then describe the architecture we implemented and that oilers an interface for controlling access to Web services.
机译:基于XML的Web服务最重要的功能之一就是可以通过Internet轻松访问它们,但这使它们容易受到一系列安全威胁的攻击。使Web服务的安全性如此具有挑战性的是它们的分布式和异构性质。由于现代经济中Web服务的飞速发展,用于控制Web服务访问的访问控制策略规范成为一个新兴的研究领域。两种使用XML的相关访问控制语言是WS-Policy和XACML。这两种语言之间的主要概念差异在于,尽管XACML基于定义明确的模型,该模型提供了访问控制安全策略及其工作的形式化表示,但是WS-Policy的开发并未考虑此建模阶段。在本文中,我们批评WS-Policy指出了它的一些缺点。然后,我们描述我们实现的体系结构,并为控制Web服务访问的接口加油。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号