首页> 外国专利> Method and system for synchronized access control in a web services environment

Method and system for synchronized access control in a web services environment

机译:Web服务环境中用于同步访问控制的方法和系统

摘要

Access controls for a Web service (which controls are based on abstract WSDL definitions) are defined for a WSDL defined protected object space and, as such, are loosely coupled with the concrete WSDL binding derived from those definitions, preferably on a per binding level. This WSDL-defined POS is in turn loosely bound to a resource-specific protected object space definition. This loose coupling is leveraged to allow changes (e.g., updates) to the abstract WSDL binding's protected object space to be transitively applied to the application-specific protected object space. If appropriate, changes to the resource-specific protected object space may be applied to the WSDL's protected object space. Thus, according to the invention, the coupling may be one-way (typically, from the WSDL POS to the resource level POS) or two-way (from the WSDL POS to the resource level POS and vice versa). This technique ensures that different security policies are not applied unintentionally to the same resource (for example, one at the Web services entry level, and the other at the resource level). By synchronizing the protected object spaces in the manner described, neither the entity that deploys the application nor the security administrator need to be aware of the differences between the Web service request and the resource request.
机译:Web服务的访问控件(控件基于抽象WSDL定义)是为WSDL定义的受保护对象空间定义的,因此,它们与从这些定义派生的具体WSDL绑定松散地结合在一起,最好是在每个绑定级别上。该WSDL定义的POS依次松散地绑定到特定于资源的受保护对象空间定义。利用这种松散耦合,可以将对抽象WSDL绑定的受保护对象空间的更改(例如,更新)可传递地应用到特定于应用程序的受保护对象空间。如果合适,可以将对特定于资源的受保护对象空间的更改应用于WSDL的受保护对象空间。因此,根据本发明,耦合可以是单向的(通常是从WSDL POS到资源级别POS)或双向的(从WSDL POS到资源级别POS,反之亦然)。此技术确保不会将不同的安全策略无意地应用于同一资源(例如,一个在Web服务入口级别,而另一个在资源级别)。通过以上述方式同步受保护的对象空间,部署应用程序的实体和安全管理员都不需要知道Web服务请求和资源请求之间的差异。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号