首页> 外文期刊>Services Computing, IEEE Transactions on >Expressive and Deployable Access Control in Open Web Service Applications
【24h】

Expressive and Deployable Access Control in Open Web Service Applications

机译:开放Web服务应用程序中的可表达和可部署访问控制

获取原文
获取原文并翻译 | 示例

摘要

Traditional access control solutions, based on preliminary identification and authentication of the access requester, are not adequate for the context of open web service systems, where servers generally do not have prior knowledge of the requesters. The research community has acknowledged such a paradigm shift and several investigations have been carried out for new approaches to regulate access control in open dynamic settings. Typically based on logic, such approaches, while appealing for their expressiveness, result not applicable in practice, where simplicity, efficiency, and consistency with consolidated technology are crucial. The eXtensible Access Control Markup Language (XACML) has established itself as the emerging technological solution for controlling access in an interoperable and flexible way. Although supporting the most common policy representation mechanisms and having acquired a significant spread in the research community and the industry, XACML still suffers from some limitations which impact its ability to support actual requirements of open web-based systems. In this paper, we provide a simple and effective formalization of novel concepts that have to be supported for enforcing the new access control paradigm needed in open scenarios, toward the aim of providing an expressive solution actually deployable with today's technology. We illustrate how the concepts of our model can be deployed in the XACML standard by exploiting its extension points for the definition of new functions, and introducing a dialog management framework to enable access control interactions between web service clients and servers.
机译:基于访问请求者的初步标识和认证的传统访问控制解决方案不适用于开放Web服务系统的环境,在开放Web服务系统中,服务器通常不具有请求者的先验知识。研究界已经意识到了这种范式的转变,并且已经针对开放式动态环境中调节访问控制的新方法进行了多项研究。通常,这些方法基于逻辑,尽管它们具有表现力,但其结果在实践中并不适用,因为简单性,效率和与整合技术的一致性至关重要。可扩展访问控制标记语言(XACML)已将自身确立为一种新兴的技术解决方案,用于以可互操作和灵活的方式控制访问。尽管XACML支持最常见的策略表示机制,并在研究界和整个行业中得到了广泛普及,但是XACML仍然受到一些局限性的影响,影响了其支持基于开放式Web系统的实际需求的能力。在本文中,我们提供了新颖有效的概念的简单有效的形式化,为了支持在开放方案中执行新的访问控制范式,必须提供新颖的概念,以期提供一种可在当今技术中实际部署的表达性解决方案。我们通过利用模型的扩展点定义新功能,并介绍一个对话框管理框架来实现Web服务客户端和服务器之间的访问控制交互,来说明如何在XACML标准中部署模型的概念。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号