...
首页> 外文期刊>International journal of information technology and web engineering >Access Control and Information Flow Control for Web Services Security
【24h】

Access Control and Information Flow Control for Web Services Security

机译:Web服务安全性的访问控制和信息流控制

获取原文
获取原文并翻译 | 示例
           

摘要

With the advancement of web services technology, security has become an increasingly important issue. Various security standards have been developed to secure web services at the transport and message level, but application level has received less attention. The security solutions at the application level focus on access control which cannot alone ensure the confidentiality and integrity of information. The solution proposed in this paper consists on a hybrid model that combines access control (AC) and information flow control (IFC). The AC mechanism uses the concept of roles and attributes to control user access to web services' methods. The IFC mechanism uses labels to control how the roles access to the system's objects and verify the information flows between them to ensure the information confidentiality and integrity. This manuscript describes the model, gives the demonstration of the IFC model safety, presents the modeling and implementation of the model and a case study.
机译:随着Web服务技术的进步,安全性已成为越来越重要的问题。已经开发了各种安全标准以在传输和消息级别保护Web服务,但是应用程序级别受到的关注较少。应用程序级别的安全解决方案侧重于访问控制,访问控制不能单独确保信息的机密性和完整性。本文提出的解决方案基于一个混合模型,该模型结合了访问控制(AC)和信息流控制(IFC)。 AC机制使用角色和属性的概念来控制用户对Web服务方法的访问。 IFC机制使用标签来控制角色如何访问系统对象并验证它们之间的信息流,以确保信息的机密性和完整性。该手稿描述了模型,给出了IFC模型安全性的演示,介绍了模型的建模和实现以及案例研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号