...
首页> 外文期刊>Internet Research: Electronic Networking Applications and Policy >A metadata-based access control model for web services
【24h】

A metadata-based access control model for web services

机译:Web服务的基于元数据的访问控制模型

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - Provide a secure solution for web services (WS). A new interoperable and distributed access control for WS is presented. Design/methodology/approach - Based on the separation of the access control (AC) and authorization function. Findings - Mechanisms presented allow seamless integration of external authorization entities in the AC system. The Semantic Policy Language (SPL) developed facilitates specification of policies and semantic policy validation. SPL specifications are modular and can be composed without ambiguity. Also addressed was the problem of the association of policies to resources (WS or their operations) in a dynamic, flexible and automated way. Research limitations/implications - The ACProxy component is currently under development. Ongoing work is focused on achieving a richer "use control" for some types of WS. Practical implications - Administrators of WS can specify AC policies and validate them to find syntactic and semantic errors. Components for automated validation of policies at different levels are included. This ensures that the AC policies produce the desired effects, facilitating the creation and maintenance of policies. It also provides mechanisms for the use of interoperable authorizations. Originality/value - A practical system that provides a secure solution to AC for WS. To the best of one's knowledge, no other system provides mechanisms for semantic validation of policies based on external authorization entities. Likewise, the mechanisms for interoperability of external authorization entities are also novel. The system provides content-based access control and a secure, decentralized and dynamic solution for authorization that facilitates the management of complex systems and enhances the overall security of the AC.
机译:目的-为Web服务(WS)提供安全的解决方案。提出了一种针对WS的新的可互操作和分布式访问控制。设计/方法/方法-基于访问控制(AC)和授权功能的分离。调查结果-提出的机制允许将外部授权实体无缝集成到AC系统中。开发的语义策略语言(SPL)有助于策略规范和语义策略验证。 SPL规范是模块化的,可以毫无歧义地组成。还解决了以动态,灵活和自动化的方式将策略与资源(WS或其操作)关联的问题。研究局限性/含义-ACProxy组件目前正在开发中。正在进行的工作集中在为某些类型的WS实现更丰富的“使用控制”上。实际的意义-WS的管理员可以指定AC策略并对其进行验证,以发现语法和语义错误。包括用于自动验证不同级别策略的组件。这样可以确保AC策略产生期望的效果,从而促进策略的创建和维护。它还提供了使用可互操作授权的机制。创意/价值-一种实用的系统,可为WS的AC提供安全的解决方案。据我所知,没有其他系统提供基于外部授权实体的策略语义验证机制。同样,外部授权实体的互操作性机制也很新颖。该系统提供基于内容的访问控制以及用于授权的安全,分散和动态解决方案,从而简化了复杂系统的管理并增强了AC的整体安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号